Product
high
advisory
Flooding Dropper npm Supply Chain Campaign
3 TTPsAn automated supply chain campaign targeting npm, deploying multi-stage loaders across 850+ malicious packages that utilize DNS TXT fallback for C2 and reflective payload execution.
npm registry
supply-chain
npm
malware
persistence
evasion
remote-access
3t
critical
advisory
Denying the Worm: Detecting SANDWORM_MODE and AI Toolchain Supply Chain Attacks
3 rules 14 TTPs 8 IOCsThe SANDWORM_MODE campaign is a multi-stage npm supply chain worm that targets AI-augmented development workflows by exploiting runtime behaviors of AI coding assistants and CI/CD pipelines, leading to credential theft, supply chain poisoning, and persistence through obfuscated loaders, credential harvesting, and malicious Git hooks.
npm +16
supply-chain-attack
git
ai-toolchain
development-workflow
code-injection
credential-theft
persistence
evasion
3r
14t
8i
updated
high
advisory
Shai-Hulud Campaign Activity
20 IOCsTracking brief for the Shai-Hulud campaign; individual sightings are folded in as reported.
jscrambler 8.14.0 +102
campaign
shai-hulud
20i
updated