skip to content
astropod
sign in
news
Product news and updates from the Gastropod team.
tagged
npm ×
ApostropheCMS's Critical Auth Bypass
2026-08-01 15:02:47 · Chris
vulnerability-intelligence
software-supply-chain-security
npm
+3
node-js
prototype-pollution
transitive-dependencies
ViteVenom: expansion of the ChainVeil campaign
2026-07-21 19:01:22 · last edited 2026-07-21 19:02:29 · Chris
vulnerability-intelligence
sbom
software-supply-chain-security
+3
npm
crypto
credential-theft
Inside the Injective SDK Wallet-Key Theft
2026-07-17 12:49:28 · Chris
vulnerability-intelligence
software-supply-chain-security
npm
+2
credential-theft
crypto
Asyncapi NPM Supply Chain Attack
2026-07-16 22:24:44 · Chris
vulnerability-intelligence
software-supply-chain-security
npm
+2
github-actions
provenance
The npm Package That Only Turned Evil When You Used It
2026-07-16 02:10:15 · Chris
vulnerability-intelligence
software-supply-chain-security
npm
+2
credential-theft
crypto
Paysafe/Skrill/Neteller fake SDK/Typosquat Campaign
2026-07-16 01:00:10 · last edited 2026-07-16 01:33:25 · Chris
vulnerability-intelligence
software-supply-chain-security
npm
+3
pypi
typosquatting
credential-theft
The jscrambler npm Compromise
2026-07-16 00:48:52 · Chris
vulnerability-intelligence
software-supply-chain-security
npm
+2
credential-theft
dependency-management
Inside the AsyncAPI "Miasma" Attack: When the Pipeline Itself Becomes the Attacker
2026-07-16 00:34:52 · Chris
vulnerability-intelligence
software-supply-chain-security
supply-chain-attack
+3
npm
ci-cd-security
github-actions