Company
npm
npm is a package manager for the JavaScript programming language, providing a repository of software packages and tools for developers to share and reuse code.
Why it’s in the news: It is in the news due to a widespread supply chain attack, the ChainDrop worm, which has infected over 400 of its packages with billions of monthly installs.
Latest on npm
- ChainDrop worm crawls into npm supply chain, evades standard defenses
- Six npm Packages Read C2 Addresses From Ethereum Wallet
- The Shai-Hulud npm worm didn't fake its security check — it earned a legitimate one
- Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack
- ChainDrop Worm Hits 400+ npm Packages with Two Billion Monthly Installs
- ChainDrop credential stealing worm infects over 400 npm packages
- By midday, security firm Aikido counted at least 868 compromised packages across 1,381 versions, together carrying over two billion monthly installs, a total still climbing.
- supply chain attack aimed at stealing authentication credentials from the npm ecosystem
Connections
3 entities linked to npm across the news graph.
Under pressure from (2)
Also connected to (1)