Company

npm

npm is a package manager for the JavaScript programming language, providing a repository of software packages and tools for developers to share and reuse code.

Why it’s in the news: It is in the news due to a widespread supply chain attack, the ChainDrop worm, which has infected over 400 of its packages with billions of monthly installs.

Latest on npm

  • ChainDrop worm crawls into npm supply chain, evades standard defenses
  • Six npm Packages Read C2 Addresses From Ethereum Wallet
  • The Shai-Hulud npm worm didn't fake its security check — it earned a legitimate one
  • Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack
  • ChainDrop Worm Hits 400+ npm Packages with Two Billion Monthly Installs
  • ChainDrop credential stealing worm infects over 400 npm packages
  • By midday, security firm Aikido counted at least 868 compromised packages across 1,381 versions, together carrying over two billion monthly installs, a total still climbing.
  • supply chain attack aimed at stealing authentication credentials from the npm ecosystem

Connections

3 entities linked to npm across the news graph.

Under pressure from (2)
Also connected to (1)