npm Payment SDK Malware Hits zahlen, voxepay, simplipayng
Malicious npm packages posing as payment and checkout SDKs (simplipayng, zahlen, voxepay) were flagged as critical malware on August 6, 2026.
One in-depth article every day on the newest supply chain attack or software security incident: what happened, who is affected, and what to do about it. Every article is grounded in the incident catalog and cites primary sources.
Malicious npm packages posing as payment and checkout SDKs (simplipayng, zahlen, voxepay) were flagged as critical malware on August 6, 2026.
keyv and cacheable npm packages, with billions of monthly downloads, were hijacked by a Shai-Hulud worm that steals CI, cloud and developer credentials.
A firmware flaw in Coldcard hardware wallets let attackers drain about $89M in bitcoin, and malicious npm and PyPI packages now target affected users.
Two npm packages, tailwindcss-anim and tailwind-anim, were flagged as critical malware for typosquatting the popular tailwindcss-animate plugin.
Eight npm packages sharing the test-dev prefix were flagged as critical malware on August 1, 2026. Who is affected, how to check your lockfiles, and how to remediate.
A 2026-08-01 malware wave added 22 npm and 3 PyPI packages that copy companies' internal library names, a classic dependency confusion pattern.
A malicious n8n community node, n8n-nodes-trust-me-im-totally-safe, was flagged critical on npm on July 30, 2026, amid a same-day wave of malicious packages.
Eight @antv npm packages plus roughly 16 other npm packages and one PyPI package were flagged with malicious code on July 28, 2026. Who is affected and how to check.
Trojanized mrmustard 0.7.4 on PyPI stole SSH keys, cloud credentials and Kubernetes config from developers. How to check if you are affected.
Attackers are abusing GitHub Actions runners as distributed infrastructure to exploit cPanel and WHM servers and steal cloud credentials, Socket says.
Malicious npm packages flagged on July 23, 2026 typosquat ethers, bs58 and bcryptjs to target crypto developers and steal wallet keys.
On July 21, 2026, more than two dozen malicious PyPI and npm packages were flagged, typosquatting Python libraries and even a Debian system package.
Our catalog flagged 23 malicious NuGet packages on July 20, 2026 that impersonate .NET libraries like Solnet and Tessa. Check your builds now.
RubyGems saw over two dozen new malicious gems flagged on July 18, 2026, extending a months-long flood that abuses the registry as a data dead drop.
Malicious npm packages anthropic-claude-latest, ai-pro-sdk, chain-sdk-js and theta-sdk-js impersonate AI and crypto SDKs to hit developers.
Attackers pushed a poisoned commit to AsyncAPI's next branch and let its own GitHub Actions pipeline publish four npm packages carrying Miasma.
IronWorm, a Rust-based self-replicating npm worm, keeps infecting WeaveDB and Arweave crypto packages, stealing developer, cloud and wallet secrets.
The official jscrambler npm package was compromised. Version 8.14.0 ran a malicious preinstall binary that dropped a Rust infostealer at install time.
Malware in 32 @redhat-cloud-services npm packages ran the Miasma credential worm via a preinstall hook. See who is affected and how to remediate.
Malicious npm packages logged on 2026-07-10 use dependency confusion, copying internal package names that match Epic, LinkedIn and Luminary Cloud.
npm v12 ships in July 2026 and blocks dependency install scripts by default, closing the postinstall vector behind a year of npm supply chain attacks.
A wave of malicious npm packages flagged July 7-8, 2026 impersonates AI, MCP, and crypto developer tools to steal credentials and inject rogue MCP servers.