Attackers performed an email takeover attack on a dormant maintainer account and published new node-ipc versions containing ...
Hackers have injected credential-stealing malware into newly published versions of node-ipc, a popular inter-process communication package, in a new supply chain attack targeting npm. The node-ipc ...
TanStack has released a detailed postmortem describing a sophisticated supply-chain attack that compromised 42 npm packages ...
Sometime around the last week of May 2026, attackers uploaded poisoned packages to three of the most widely used software ...