NPM install hook exfiltrates environment
credential-theft/env
What we caught this week while monitoring over 163,702,362 artifacts across 47 ecosystems. Campaigns that impact multiple packages are collapsed into a single entry with their siblings.
NPM install hook exfiltrates environment
Malicious embedded archive member
curl-piped-to-shell remote loader
npm postinstall installs unrestricted Claude worker
AMSI patch evasion in ScreenToGif
Trojanized tailwindcss dependency
clipboard stealing, UI spying, evasion