Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AITrojanized npm Packages Decode C2 IP From Ethereum Recipient Addresses
Cybersecurity researchers have identified an advanced variant of the EtherHiding technique that conceals command-and-control server IP addresses within fake Ethereum transaction recipient addresses. Two malicious npm packages, 'bianira-ui' and 'fluid-type-ui,' were discovered using this 'NullReceiver' method, which leverages empty Ethereum transfers as a dead drop resolver mechanism to evade detec
AIKeyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks
A credential-stealing worm originating in the npm package keyv@6.0.0 rapidly propagated across the npm ecosystem on August 4, 2026, infecting hundreds of packages across multiple organizations. The malware, which includes hooks targeting Claude Code and VS Code development environments, was confirmed in at least 353-868 packages depending on the monitoring source, representing a significant supply
AI18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
Cybersecurity researchers have identified 18 malicious npm packages targeting Alibaba developer tool users with a cross-platform remote access trojan (RAT). The attack represents a sophisticated software supply chain compromise specifically aimed at Chinese-speaking development environments, with one package named 'lib-mtop' mimicking a legitimate private Alibaba package.
AIAmazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet
Amazon has attributed the September 2025 hijacking of popular npm packages 'debug' and 'chalk' to North Korea's Sapphire Sleet threat group. The attack, which remained unattributed for ten months, involved phishing a maintainer through a lookalike npm domain and deploying wallet-draining scripts across at least 18 packages with over 2 billion combined weekly downloads.
AITwo Compromised joyfill npm Packages Run RAT When Imported Into Node.js
Two beta release versions of npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) from the DEV#POPPER malware family. The malicious packages execute encrypted JavaScript code automatically when imported into Node.js applications, creating a supply chain security risk for developers using these components.
AI144 Mastra npm Packages Compromised via Hijacked Contributor Account
A software supply chain attack codenamed 'easy-day-js' compromised 144 npm packages within the Mastra namespace, a popular framework for building AI applications. The attack was executed through a hijacked contributor account (ehindero) that mass-published malicious packages, posing significant risks to organizations using this JavaScript/TypeScript framework.
AIMiasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm
A supply chain attack dubbed Miasma has compromised Red Hat npm packages (@redhat-cloud-services) to deploy credential-stealing malware and a self-propagating worm on developer systems. The campaign employs Mini Shai-Hulud tactics including install-time execution, credential harvesting, CI/CD pipeline targeting, and encrypted data exfiltration. This incident represents a significant threat to ente
AIOpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack
A malicious supply chain attack targeting developers has been discovered in the codexui-android npm package, which masquerades as a legitimate remote web UI for OpenAI Codex. The compromised package, still available on npm and GitHub, has attracted over 29,000 weekly downloads and is designed to steal OpenAI Codex authentication tokens from unsuspecting developers.
AIStealer Backdoor Found in 3 Node-IPC Versions Targeting Developer Secrets
Cybersecurity researchers have identified malicious code in three versions of the popular npm package node-ipc (versions 9.1.6, 9.2.3, and 12.0.1), which contains stealer backdoor functionality targeting developer credentials and secrets. The compromised package poses significant supply chain security risks to enterprise development environments that rely on Node.js dependencies.
