npm Dependency Confusion Hits Akamai, Fastly, Twilio Names
On August 15, 2026, npm malware trackers flagged dependency-confusion packages impersonating Akamai, Fastly, Twilio and GCP internal names, plus recon beacons.
One in-depth article every day on the newest supply chain attack or software security incident: what happened, who is affected, and what to do about it. Every article is grounded in the incident catalog and cites primary sources.
On August 15, 2026, npm malware trackers flagged dependency-confusion packages impersonating Akamai, Fastly, Twilio and GCP internal names, plus recon beacons.
Backdoored LiteLLM PyPI releases 1.82.7 and 1.82.8 stole cloud, SSH and Kubernetes secrets. New CloudSEK data ties the Trivy hack to 2,500+ orgs.
Researchers found nearly 800 malicious npm packages that run WEL1DROPPER, a downloader delivering a RAT and infostealer on Windows, macOS and Linux.
Malicious npm packages impersonating the chai assertion library (chai-tracker, chai-as-promised-plus and more) were flagged as critical malware on 2026-08-10.
Novee Security showed at Black Hat 2026 that one public GitHub issue could hijack Gemini CLI, Claude Code and Codex. Google rated the Gemini CLI flaw 10.0.
The Flooding Dropper npm campaign has pushed around 850 malicious packages from disposable accounts, dropping a cross-platform RAT and infostealer.
Malicious npm packages posing as payment and checkout SDKs (simplipayng, zahlen, voxepay) were flagged as critical malware on August 6, 2026.
keyv and cacheable npm packages, with billions of monthly downloads, were hijacked by a Shai-Hulud worm that steals CI, cloud and developer credentials.
A firmware flaw in Coldcard hardware wallets let attackers drain about $89M in bitcoin, and malicious npm and PyPI packages now target affected users.
Two npm packages, tailwindcss-anim and tailwind-anim, were flagged as critical malware for typosquatting the popular tailwindcss-animate plugin.
Eight npm packages sharing the test-dev prefix were flagged as critical malware on August 1, 2026. Who is affected, how to check your lockfiles, and how to remediate.
A 2026-08-01 malware wave added 22 npm and 3 PyPI packages that copy companies' internal library names, a classic dependency confusion pattern.
A malicious n8n community node, n8n-nodes-trust-me-im-totally-safe, was flagged critical on npm on July 30, 2026, amid a same-day wave of malicious packages.
Eight @antv npm packages plus roughly 16 other npm packages and one PyPI package were flagged with malicious code on July 28, 2026. Who is affected and how to check.
Trojanized mrmustard 0.7.4 on PyPI stole SSH keys, cloud credentials and Kubernetes config from developers. How to check if you are affected.
Attackers are abusing GitHub Actions runners as distributed infrastructure to exploit cPanel and WHM servers and steal cloud credentials, Socket says.
Malicious npm packages flagged on July 23, 2026 typosquat ethers, bs58 and bcryptjs to target crypto developers and steal wallet keys.
On July 21, 2026, more than two dozen malicious PyPI and npm packages were flagged, typosquatting Python libraries and even a Debian system package.
Our catalog flagged 23 malicious NuGet packages on July 20, 2026 that impersonate .NET libraries like Solnet and Tessa. Check your builds now.
RubyGems saw over two dozen new malicious gems flagged on July 18, 2026, extending a months-long flood that abuses the registry as a data dead drop.
Malicious npm packages anthropic-claude-latest, ai-pro-sdk, chain-sdk-js and theta-sdk-js impersonate AI and crypto SDKs to hit developers.
Attackers pushed a poisoned commit to AsyncAPI's next branch and let its own GitHub Actions pipeline publish four npm packages carrying Miasma.
IronWorm, a Rust-based self-replicating npm worm, keeps infecting WeaveDB and Arweave crypto packages, stealing developer, cloud and wallet secrets.
The official jscrambler npm package was compromised. Version 8.14.0 ran a malicious preinstall binary that dropped a Rust infostealer at install time.
Malware in 32 @redhat-cloud-services npm packages ran the Miasma credential worm via a preinstall hook. See who is affected and how to remediate.
Malicious npm packages logged on 2026-07-10 use dependency confusion, copying internal package names that match Epic, LinkedIn and Luminary Cloud.
npm v12 ships in July 2026 and blocks dependency install scripts by default, closing the postinstall vector behind a year of npm supply chain attacks.
A wave of malicious npm packages flagged July 7-8, 2026 impersonates AI, MCP, and crypto developer tools to steal credentials and inject rogue MCP servers.