Curated Cyber Threat Intelligence
Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports
Filtered Reports
3 / 3 results
highbug_reportVulnerabilitybug_reportVulnerability
ChainDrop npm worm infects 400+ packages, steals secrets via blockchain C2
Over 400 npm packages including widely used packages like keyv and cacheable-request. Affects developer workstations, CI/CD pipelines (especially GitHub Actions), cloud environments, and downstream software users.
npm6 Aug · 20:26 UTC
criticalbug_reportVulnerabilitybug_reportVulnerability
Credential-stealing worm compromises 400+ npm packages via auto-propagation
Over 400 npm packages across multiple unrelated publishers, including keyv, flat-cache, cache-manager, and other major enterprise software ecosystem packages. Affects developer workstations and CI/CD environments with npm lifecycle scripts enabled.
npm4 Aug · 21:46 UTC
criticalbug_reportVulnerabilitybug_reportVulnerability
ChainDrop worm compromises 1,300+ npm packages with 2B monthly downloads
Over 1,300 npm packages (1,381 versions) including Keyv, Cacheable, flat-cache, and file-entry-cache. Attack originated from compromised GitHub account of Keyv maintainer.
npm4 Aug · 13:24 UTC