BackBox.org News
  • BackBox.org
  • Linux
  • Community
  • News
  • Services
  • Sitemap
  • Contact
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
40 npm Packages Compromised in Supply Chain Attack Using bundle.js to Steal Credentials

40 npm Packages Compromised in Supply Chain Attack Using bundle.js to Steal Credentials

September 16, 2025/in General News

Cybersecurity researchers have flagged a fresh software supply chain attack targeting the npm registry that has affected more than 40 packages that belong to multiple maintainers.
“The compromised versions include a function (NpmModule.updatePackage) that downloads a package tarball, modifies package.json, injects a local script (bundle.js), repacks the archive, and republishes it, enabling

The Hacker News – ​Read More

Share this entry
  • Share on Facebook
  • Share on X
  • Share on WhatsApp
  • Share on LinkedIn
  • Share on Vk
  • Share on Reddit
  • Share by Mail
https://www.backbox.org/wp-content/uploads/2018/09/website_backbox_text_black.png 0 0 admin https://www.backbox.org/wp-content/uploads/2018/09/website_backbox_text_black.png admin2025-09-16 06:07:122025-09-16 06:07:1240 npm Packages Compromised in Supply Chain Attack Using bundle.js to Steal Credentials
Search Search
Copyright © BackBox.org
  • Link to X
  • Link to Facebook
  • Link to LinkedIn
  • Link to Youtube
  • Link to Telegram
Link to: In 2 years, half of all service calls will be resolved by AI – survey Link to: In 2 years, half of all service calls will be resolved by AI – survey In 2 years, half of all service calls will be resolved by AI – survey Link to: Windows 11 upgrade failed? These are my 4 most powerful troubleshooting secrets Link to: Windows 11 upgrade failed? These are my 4 most powerful troubleshooting secrets Windows 11 upgrade failed? These are my 4 most powerful troubleshooting sec...
Scroll to top Scroll to top Scroll to top