Find a story
Search Spins
Search titles, summaries, and missing voices across published articles — press releases, announcements, and media coverage.
0 results for “package manager”
Massive ChainDrop npm supply-chain attack infects hundreds of packages
A self-propagating malware campaign dubbed 'ChainDrop' has infected over 1,300 npm packages totaling 2 billion monthly downloads, representing a large-scale, automated supply-chain compromise in the JavaScript ecosystem.
Aug 4, 2026
Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
Amazon attributed recent npm supply-chain attacks involving malicious packages 'Debug' and 'Chalk' to North Korean state-sponsored actors, positioning itself as a key threat intelligence contributor in open-source security.
Jul 31, 2026
Moonstone: Modern, cross-platform Lua runtime and package manager written in Zig
A forum thread on Hacker News discusses 'Moonstone', a new Lua runtime and package manager written in Zig, with no substantive reporting or factual claims beyond the title and user comments.
Jul 18, 2026
AsyncAPI npm packages infected with credential-stealing malware
Five compromised AsyncAPI npm packages delivered credential-stealing malware via a supply-chain attack, exposing developers and downstream systems to unauthorized access and data theft.
Jul 15, 2026
Injective SDK on npm infected with cryptocurrency wallet stealer
A malicious package impersonating the Injective SDK was published to npm after attackers compromised its GitHub repository, enabling theft of cryptocurrency wallet credentials.
Jul 10, 2026
Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials
Malicious software packages impersonating legitimate payment SDKs for Paysafe, Skrill, and Neteller were distributed via npm and PyPI, enabling credential theft from developers and end users.
Jul 10, 2026