Tag
npm
Every npm story we've curated in Bowl of Data, newest issue first — part of our weekly digest across AI, security, blockchain, and engineering.
Week 29 · 2026
Read the issue →-
@asyncapi/specs (2.7M weekly downloads) got compromised today via a malicious CI commit
An attacker compromised AsyncAPI repositories to publish malicious npm packages that deploy the Miasma RAT credential stealer. The attack impacts millions of weekly downloads and utilizes advanced obfuscation and multi-channel C2 infrastructure.
Week 28 · 2026
Read the issue →-
Why a five-minute sniff test is your secret supply chain defense
The article advocates for a proactive 'sniff test' methodology to validate the integrity of SBOMs in containerized environments. It highlights how identifying omissions like unpinned packages or missing dependencies is crucial for preventing supply chain attacks.
Week 27 · 2026
Read the issue →-
Aikido acquires Root to backport open source fixes without forcing upgrades
Aikido Security has completed a $70 million acquisition of Root to introduce automated backporting of security patches. The move aims to remediate critical vulnerabilities in existing open source dependencies without forcing developers to undergo complex version upgrades.
Week 24 · 2026
Read the issue →-
For the 2nd time in weeks, Microsoft packages laced with credential stealer
Threat actors have successfully compromised dozens of Microsoft-owned repositories to deploy the Miasma malware via supply-chain attacks. The malware is designed to steal cloud credentials and spread laterally through developer environments by exploiting AI coding agents.
Week 23 · 2026
Read the issue →-
Red Hat npm packages compromised to steal developer credentials
More than 30 Red Hat npm packages were compromised in a supply-chain attack using the Miasma malware to steal developer credentials. The attack was executed via a compromised GitHub account and targeted various cloud and infrastructure secrets.
Week 20 · 2026
Read the issue →-
Postmortem: TanStack npm supply-chain compromise
An attacker successfully compromised 42 TanStack npm packages by chaining GitHub Actions cache poisoning with OIDC token extraction. The breach allowed for the unauthorized publication of malicious versions that could exfiltrate sensitive cloud and infrastructure credentials.
-
Official CheckMarx Jenkins package compromised with infostealer
The TeamPCP hacker group has compromised the Checkmarx Jenkins AST plugin by leveraging credentials stolen from a previous Trivy scanner breach. This supply-chain attack allows for the delivery of credential-stealing malware to developer environments.
Free weekly digest
Get next Saturday’s issue in your inbox
The week’s most relevant AI, security, blockchain, and engineering stories — curated, summarised, and reviewed by humans. No spam, unsubscribe anytime.
Subscribe — it’s free