On March 16, 2026, StepSecurity Threat Intel was the first to detect and report malicious releases in two popular React Native npm packages — react-native-international-phone-number and ...
A week-long automated attack campaign targeted CI/CD pipelines across major open source repositories, achieving remote code execution in multiple targets. The attacker, an autonomous bot called ...
56 supply chain attacks in 12 months, each with a StepSecurity Threat Center alert. The data, the worms, the Team PCP numbers, and how to defend.
An external GitHub user exploited an exposed npm publishing workflow for @7nohe/openapi-react-query-codegen and shipped ten malicious versions that run attacker code during installation.
How Utility Warehouse Secured Its Software Supply Chain Across CI/CD, NPM, and Developer Machines with StepSecurity Utility Warehouse, the UK’s leading multiservice provider trusted by over 1.4 ...
Have a question or feedback? We would love to hear from you. Submit the form below or email us directly at info@stepsecurity.io ...
@bitwarden/cli@2026.4.0 — the official command-line interface for the Bitwarden password manager — was found compromised on npm. A malicious preinstall hook silently bootstraps the Bun JavaScript ...
Active Supply Chain Attack: Malicious node-ipc Versions Published to npm StepSecurity has detected multiple malicious releases of the popular node-ipc npm package. Three versions are currently known ...
Malicious 2773 beta versions of @joyfill/components and @joyfill/layouts carry an obfuscated remote access trojan and credential stealer that run on import. Here is how it works and how to check if ...
Several packages in the @redhat-cloud-services npm scope were found to carry malicious payloads that fire via a preinstall hook on every npm install. The affected versions span multiple packages ...
The StepSecurity threat intelligence team discovered that dev-protocol — a verified GitHub organization with 568 followers belonging to a legitimate Japanese DeFi project — has been hijacked and is ...
StepSecurity's AI Package Analyst and Harden-Runner detected the compromise of axios, the largest npm supply chain attack on a single package by download count, before any public disclosure existed.