#credential-stealing


​ ​AsyncAPI npm packages infected with credential-stealing malware

Jul 15, 2026 // 18:56

Five malicious versions of AsyncAPI packages were published to the Node Package Manager (npm) in a supply-chain attack that delivered a remote access trojan with […]

Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm

Jun 1, 2026 // 22:14

A new Mini Shai-Hulud supply chain attack campaign, codenamed Miasma, has compromised @redhat-cloud-services packages to steal credentials and secrets from developer machines and deliver a […]

TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO

May 25, 2026 // 19:10

A new coordinated cross-ecosystem software supply chain attack campaign has targeted npm, PyPI, and Crates.io to distribute credential-stealing malware. The campaign, codenamed TrapDoor, spans more […]

Laravel Lang packages hijacked to deploy credential-stealing malware

May 23, 2026 // 23:57

A supply chain attack targeting the Laravel Lang localization packages has exposed developers to a sophisticated credential-stealing malware campaign after attackers abused GitHub version tags […]

SAP npm Packages Compromised by “Mini Shai-Hulud” Credential-Stealing Malware

Apr 29, 2026 // 19:32

Cybersecurity researchers are sounding the alarm about a new supply chain attack campaign targeting SAP-related npm Packages with credential-stealing malware. According to reports from Aikido […]