As a worm spread through hundreds of npm packages in 2025, it didn't exploit a vulnerability – it exploited the architecture.
This weekly recap brings those stories together in one place. No overload, no noise. Read on to see what shaped the threat ...
Infosecurity has selected five of the most significant vulnerability exploitation campaigns of 2025 that led to major ...
Researchers uncovered 27 malicious npm packages used over five months to host phishing pages that steal credentials from ...
Shai Hulud is a malware campaign first observed in September targeting the JavaScript ecosystem that focuses on supply chain ...
Malicious npm package posing as a WhatsApp Web API library operated for months as a functional dependency while stealing ...