Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
25 / 36 results
highbug_reportVulnerabilityAttackers abuse npm mirrors as free hosting for Cloudflare phishing pages
npm registry and public mirrors (UNPKG, npmmirror). Organizations using these mirrors to serve package content. At least 24 malicious packages identified hosting fake Cloudflare CAPTCHA pages.
highbug_reportVulnerability24 npm packages abuse unpkg mirrors as phishing infrastructure
24 malicious npm packages (e.g., bgzxcuite2, prezdentkxheiw, egair0810) hosted on npm registry and mirrored on unpkg.com and similar CDN services. Affects users who click links to these mirrored HTML pages, not developers installing packages directly…
highbug_reportVulnerability14 trojanized npm packages deliver AI-powered RedC2 4.0 Linux backdoor
14 npm packages (streak-metrics-math, kit-map-vim, streak-map-cache, streak-map-kit, map-streak-kit, streak-cache-map, streak-calc-metrics, streak-calc-math, streak-math-abz, streak-metricsaz, streak-math-metrics, streak-metricazbd, streak-metricsazb…
criticalbug_reportVulnerabilityNearly 800 malicious npm packages deliver cross-platform RAT via typosquatting
npm registry: ~800 packages using typosquatting and AI-generated names. Targets all Node.js developers on Windows, macOS (x64/ARM64), and Linux (x64/ARM64). Delivers WEL1DROPPER leading to Sliver C2 framework and platform-specific infostealers.
highbug_reportVulnerabilityChainDrop npm worm infects 400+ packages, steals secrets via blockchain C2
Over 400 npm packages including widely used packages like keyv and cacheable-request. Affects developer workstations, CI/CD pipelines (especially GitHub Actions), cloud environments, and downstream software users.
highbug_reportVulnerabilityTrojanized npm packages use blockchain to hide C2 IPs in supply chain attack
Two npm packages: "bianira-ui" (109 downloads) and "fluid-type-ui" (587 downloads), published July 28, 2026 by users "npmuser1101" and "npmuser3002". Packages now removed from npm.
criticalbug_reportVulnerabilityCredential-stealing worm compromises 400+ npm packages via auto-propagation
Over 400 npm packages across multiple unrelated publishers, including keyv, flat-cache, cache-manager, and other major enterprise software ecosystem packages. Affects developer workstations and CI/CD environments with npm lifecycle scripts enabled.
criticalbug_reportVulnerabilityChainDrop worm compromises 1,300+ npm packages with 2B monthly downloads
Over 1,300 npm packages (1,381 versions) including Keyv, Cacheable, flat-cache, and file-entry-cache. Attack originated from compromised GitHub account of Keyv maintainer.
criticalbug_reportVulnerabilitynpm worm from keyv@6.0.0 poisons 353+ packages, steals credentials via hooks
npm packages: keyv@6.0.0 and at least 353 poisoned versions across 79 package names (SafeDep verified); broader estimates reach 868 packages. Affects developers and CI/CD environments using npm clients prior to npm 12, Claude Code, and VS Code.
highbug_reportVulnerability18 malicious npm packages deliver cross-platform RAT to Alibaba developers
18 npm packages targeting Alibaba developer tool users, primarily Chinese-speaking environments. Key packages: lib-mtop (v1.0.1-1.0.3), aone-kit, aone-kit-cli, aone-sandbox, local-config-parser, smart-config-manager, and 12 others.
highbug_reportVulnerabilityNorth Korea-linked actors compromise npm packages debug, chalk, axios
Node Package Manager (npm) ecosystem: typo-crypto (March 2025), debug and chalk (September 2025, ~10% of cloud environments affected within 2 hours), axios (March 2026, 100M+ weekly downloads).
criticalbug_reportVulnerabilityNorth Korea linked to npm supply chain attacks on debug, chalk, axios
npm packages debug, chalk, axios, typo-crypto, and Mastra (over 2 billion weekly downloads combined). Attacks spanned March 2025 through March 2026. Maintainer accounts compromised via phishing; malicious code injected to steal cryptocurrency wallet…
highbug_reportVulnerabilitySeven malicious npm packages target Vite ecosystem with blockchain C2 RAT
npm package ecosystem, specifically projects using Vite frontend tooling. Seven malicious packages identified in the ViteVenom campaign. Any JavaScript/Node.js development environments that installed these packages are compromised.
highbug_reportVulnerabilityNorth Korean actors deploy malicious npm packages to steal developer secrets
npm ecosystem: malicious packages "rollup-packages-polyfill-core" and "rollup-runtime-polyfill-core" impersonating legitimate "rollup-plugin-polyfill-node".
highbug_reportVulnerabilityHijacked npm and Go packages deploy cross-platform stealer via VS Code
Compromised npm and Go packages targeting developers using Microsoft Visual Studio Code on Windows, Linux, and macOS. Attack bypasses npm v12 lifecycle script protections by abusing VS Code task execution.
highbug_reportVulnerabilityMiasma malware compromises npm packages LeoPlatform and RStreams
npm packages LeoPlatform and RStreams compromised by Miasma malware family. Attack extends to GitHub Actions workflows and Go ecosystem. Organizations using these packages or dependent projects are affected.
highbug_reportVulnerabilityMalicious npm packages deliver Windows RAT to JavaScript developers
Three npm packages (aes-decode-runner-pro, postcss-minify-selector, postcss-minify-selector-parser) published within the past month. Total downloads: 145-615 per package. Affects Windows-based development environments using npm package manager.
highbug_reportVulnerabilityNorth Korean APT compromised 140+ npm packages via Mastra AI framework
Mastra AI framework and over 140 dependent npm packages. Organizations using Mastra AI or downstream dependencies in Node.js/JavaScript applications are affected.
highbug_reportVulnerabilityWeekly threat roundup: Claude abuse, npm poisoning, phishing campaigns
Multiple platforms and products: Claude AI chat interface, npm package ecosystem (NastyC2), OAuth device-code flows, browser extensions (unspecified), macOS systems, cloud management agents, and internet-exposed edge devices.
highbug_reportVulnerabilityPoisoned npm package compromises 140+ projects via postinstall payload
140+ projects using a malicious npm package containing a hidden postinstall script. Affects Node.js/JavaScript development environments consuming npm dependencies. Specific package name not disclosed in summary.
criticalbug_reportVulnerabilitySupply chain attack compromises 144 Mastra npm packages via hijacked account
144 npm packages in the @mastra/* namespace (Mastra AI framework for JavaScript/TypeScript). Attack vector: compromised npm contributor account (ehindero). All downstream projects using affected Mastra packages are potentially impacted.
highbug_reportVulnerabilitynpm v12 disables install scripts by default to block supply chain attacks
npm version 12 and later. All Node.js projects using npm for package management. Breaking change affects packages that legitimately rely on install/postinstall lifecycle hooks.
criticalbug_reportVulnerabilitynpm supply chain attack: 50+ packages deliver IronWorm stealer and rootkit
npm ecosystem: over 50 compromised legitimate packages. Affects developers using npm for JavaScript/Node.js projects. IronWorm targets developer credentials and source code with eBPF kernel-level persistence.
highbug_reportVulnerabilityMalicious npm package codexui-android steals OpenAI tokens, 29K downloads
npm package codexui-android (all versions). Targets developers using OpenAI Codex APIs. Affects organizations with Node.js/npm development environments where this package was installed.
highbug_reportVulnerability33 malicious npm packages deployed in dependency confusion recon campaign
npm ecosystem; organizations using private npm packages with names vulnerable to dependency confusion attacks. Affects developer workstations, CI/CD pipelines, and build environments that may inadvertently install public packages instead of intended…