Find a story
Search Spins
Search titles, summaries, and missing voices across published articles — press releases, announcements, and media coverage.
3 results for “malicious packages”
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
Nearly 800 malicious npm packages were discovered delivering cross-platform remote access trojans and infostealers, exploiting AI-generated typo-squatting names to evade detection.
Aug 8, 2026
Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials
Malicious software packages impersonating legitimate payment SDKs for Paysafe, Skrill, and Neteller were distributed via npm and PyPI, enabling credential theft from developers and end users.
Jul 10, 2026
North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
North Korean threat actors associated with the Contagious Interview campaign have published 108 malicious software packages and browser extensions across npm, Packagist, Go, and Chrome Web Store under the PolinRider operation, exploiting compromised maintainer accounts to distribute malware.
Published Jul 4, 2026 · Analyzed Jul 7, 2026