Utopia Tech
▸ Engineering & Strategy Journal

Field notes from the edge.

What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.

Trojanized npm Packages Decode C2 IP From Ethereum Recipient AddressesAI
Security

Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addresses

Cybersecurity researchers have identified an advanced variant of the EtherHiding technique that conceals command-and-control server IP addresses within fake Ethereum transaction recipient addresses. Two malicious npm packages, 'bianira-ui' and 'fluid-type-ui,' were discovered using this 'NullReceiver' method, which leverages empty Ethereum transfers as a dead drop resolver mechanism to evade detec

UTUtopia Tech·1 min
Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code HooksAI
Security

Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks

A credential-stealing worm originating in the npm package keyv@6.0.0 rapidly propagated across the npm ecosystem on August 4, 2026, infecting hundreds of packages across multiple organizations. The malware, which includes hooks targeting Claude Code and VS Code development environments, was confirmed in at least 353-868 packages depending on the monitoring source, representing a significant supply

UTUtopia Tech·1 min
18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool UsersAI
Security

18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

Cybersecurity researchers have identified 18 malicious npm packages targeting Alibaba developer tool users with a cross-platform remote access trojan (RAT). The attack represents a sophisticated software supply chain compromise specifically aimed at Chinese-speaking development environments, with one package named 'lib-mtop' mimicking a legitimate private Alibaba package.

UTUtopia Tech·1 min
Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire SleetAI
Security

Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet

Amazon has attributed the September 2025 hijacking of popular npm packages 'debug' and 'chalk' to North Korea's Sapphire Sleet threat group. The attack, which remained unattributed for ten months, involved phishing a maintainer through a lookalike npm domain and deploying wallet-draining scripts across at least 18 packages with over 2 billion combined weekly downloads.

UTUtopia Tech·1 min
Two Compromised joyfill npm Packages Run RAT When Imported Into Node.jsAI
Security

Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

Two beta release versions of npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) from the DEV#POPPER malware family. The malicious packages execute encrypted JavaScript code automatically when imported into Node.js applications, creating a supply chain security risk for developers using these components.

UTUtopia Tech·1 min
144 Mastra npm Packages Compromised via Hijacked Contributor AccountAI
Security

144 Mastra npm Packages Compromised via Hijacked Contributor Account

A software supply chain attack codenamed 'easy-day-js' compromised 144 npm packages within the Mastra namespace, a popular framework for building AI applications. The attack was executed through a hijacked contributor account (ehindero) that mass-published malicious packages, posing significant risks to organizations using this JavaScript/TypeScript framework.

UTUtopia Tech·1 min
Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing WormAI
Security

Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm

A supply chain attack dubbed Miasma has compromised Red Hat npm packages (@redhat-cloud-services) to deploy credential-stealing malware and a self-propagating worm on developer systems. The campaign employs Mini Shai-Hulud tactics including install-time execution, credential harvesting, CI/CD pipeline targeting, and encrypted data exfiltration. This incident represents a significant threat to ente

UTUtopia Tech·1 min
OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain AttackAI
Security

OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack

A malicious supply chain attack targeting developers has been discovered in the codexui-android npm package, which masquerades as a legitimate remote web UI for OpenAI Codex. The compromised package, still available on npm and GitHub, has attracted over 29,000 weekly downloads and is designed to steal OpenAI Codex authentication tokens from unsuspecting developers.

UTUtopia Tech·1 min
Stealer Backdoor Found in 3 Node-IPC Versions Targeting Developer SecretsAI
Security

Stealer Backdoor Found in 3 Node-IPC Versions Targeting Developer Secrets

Cybersecurity researchers have identified malicious code in three versions of the popular npm package node-ipc (versions 9.1.6, 9.2.3, and 12.0.1), which contains stealer backdoor functionality targeting developer credentials and secrets. The compromised package poses significant supply chain security risks to enterprise development environments that rely on Node.js dependencies.

UTUtopia Tech·1 min
Skip to main content