WARPTECHNEWS · LAB
HomeAIBusinessTechArchive
WARPTECH LAB NEWS

Warptech Lab News aggrega le notizie più rilevanti da oltre 700 fonti internazionali, con classificazione AI, TL;DR sintetici e timeline cluster su singole storie.

Navigazione

  • Home
  • Archivio
  • Editor's Brief
  • Cerca
  • Il tuo account
  • Newsletter tech/AI

Informazioni legali

  • Privacy Policy
  • Termini di servizio
  • Cookie Policy

© 2026 Sparktech S.R.L. — Tutti i diritti riservati. Sito gestito e manutenuto da Sparktech S.R.L.

Sede legale: Corso Libertà 55, 13100 Vercelli (VC), Italia · P.IVA / C.F. 02835910023 · Contatti: admin@warptechlab.com

Home
Storia in 6 fonti

Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware

4 malicious npm packages with 3,006 downloads spread stealers and Phantom Bot, forcing removals and secret rotation.

Raccontata danews.bitcoin.comthehackernews.combleepingcomputer.cominfoworld.comtheregister.comsecurityweek.com

Confronto fonti

6 prospettive sulla stessa storia
AI · summaries
thehackernews.comStai leggendo1 mesi fa

Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware

4 malicious npm packages with 3,006 downloads spread stealers and Phantom Bot, forcing removals and secret rotation.

originale
theregister.com1 mesi fa

Shai-Hulud copycat worm infects yet another npm package

Plus three other stealers in three other packages, all from the same scumbag

Leggi questa versione → originale
bleepingcomputer.com1 mesi fa

Leaked Shai-Hulud malware fuels new npm infostealer campaign

The Shai-Hulud malware leaked last week is now used in new attacks on the Node Package Manager (npm) index, as infected packages emerged over the weekend.

Leggi questa versione → originale
news.bitcoin.com1 mesi fa

822K Downloads at Risk: Malicious node-ipc Versions Spotted Stealing AWS and Private Keys

Slowmist confirmed three malicious node-ipc npm versions on May 14, 2026, stealing AWS keys, SSH secrets, and .env files via DNS tunneling.

Leggi questa versione → originale
securityweek.com1 mesi fa

Over 320 NPM Packages Hit by Fresh Mini Shai-Hulud Supply Chain Attack

A fresh Mini Shai-Hulud supply chain attack has hit over 320 NPM packages, along with GitHub Actions and a VS Code extension.

Leggi questa versione → originale
infoworld.com1 mesi fa

AntV data visualization tool the latest to be hit by ongoing npm supply chain attacks

The largest incident yet is a warning that developers should urgently check package security, say experts.

Leggi questa versione → originale

Timeline cronologica

  1. venerdì 15 maggio 2026·news.bitcoin.com

    822K Downloads at Risk: Malicious node-ipc Versions Spotted Stealing AWS and Private Keys

    Slowmist confirmed three malicious node-ipc npm versions on May 14, 2026, stealing AWS keys, SSH secrets, and .env files via DNS tunneling.

  2. lunedì 18 maggio 2026·thehackernews.com

    Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware

    4 malicious npm packages with 3,006 downloads spread stealers and Phantom Bot, forcing removals and secret rotation.

  3. lunedì 18 maggio 2026·bleepingcomputer.com

    Leaked Shai-Hulud malware fuels new npm infostealer campaign

    The Shai-Hulud malware leaked last week is now used in new attacks on the Node Package Manager (npm) index, as infected packages emerged over the weekend.

  4. martedì 19 maggio 2026·infoworld.com

    AntV data visualization tool the latest to be hit by ongoing npm supply chain attacks

    The largest incident yet is a warning that developers should urgently check package security, say experts.

  5. martedì 19 maggio 2026·theregister.com

    Shai-Hulud copycat worm infects yet another npm package

    Plus three other stealers in three other packages, all from the same scumbag

  6. martedì 19 maggio 2026·thehackernews.com

    Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account

    Mini Shai-Hulud hits @antv and echarts-for-react via npm maintainer compromise, exposing 1.1M weekly downloads to credential theft.

  7. martedì 19 maggio 2026·theregister.com

    Shai-Hulud keeps burrowing: 314 npm packages infected after another account compromise

    Popular JavaScript modules including size-sensor and echarts-for-react hit as hijacked account closed GitHub warnings

  8. martedì 19 maggio 2026·bleepingcomputer.com

    New Shai-Hulud malware wave compromises 600 npm packages

    Threat actors earlier today published more than 600 malicious packages to the Node Package Manager (npm) index as part of a new Shai-Hulud supply-chain campaign.

  9. mercoledì 20 maggio 2026·news.bitcoin.com

    GitHub Worm Hits npm Packages With 16M Downloads

    A self-replicating worm that hijacks GitHub Actions pipelines to publish malicious npm packages has struck again, compromising AntV, echarts-for-react,

  10. mercoledì 20 maggio 2026·securityweek.com

    Over 320 NPM Packages Hit by Fresh Mini Shai-Hulud Supply Chain Attack

    A fresh Mini Shai-Hulud supply chain attack has hit over 320 NPM packages, along with GitHub Actions and a VS Code extension.