LIVE · cybersecurity feed
Live wire

npm

npmhigh

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver RAT

Researchers have identified seven malicious npm packages that were part of a software supply chain attack targeting the Vite frontend tooling ecosystem. These packages, dubbed ViteVenom, utilized a sophisticated four-tier blockchain-based command-and-control infrastructure across multiple networks to deliver a remote access trojan (RAT).

supply chain attackhigh

Miasma Worm Exploits Developer Credentials in Supply Chain Attacks

A sophisticated supply chain attack, dubbed Miasma, has compromised numerous npm packages, including those under the @redhat-cloud-services namespace. Attackers exploited stolen developer credentials, which lingered in underground markets for weeks before being used to poison software packages. The worm also targeted AI coding assistants, expanding its attack surface to local developer environments.