Product
npm
- First Reported
- Feb 17, 2026
- Latest Reported
- Sep 30, 2026
Reported Context (3)
- 2026, a single operator publishing under Portuguese-language accounts uploaded at least twelve packages to npm and one payload repository to GitHub. Five packages carry MAL- advisories, three are malicious but MALFEX: Malicious npm Supply-Chain Campaign Went Unadvised for 14 Months
- Researchers uncovered Kothamine Agent, an undocumented RAT linked to malicious npm packages that can control Windows systems, steal browser data, and capture audio/video on some builds. Kothamine RAT Uses Tailscale’s Tailcat for Encrypted Command-and-Control
- supply chains are increasingly becoming a serious threat. Criminal actors have managed to place malware in npm (a package manager for JavaScript programs). This malware is a worm named “Shai-Hulud” - a reference to the Shai-Hulud Detector’s Test Files Contained Executable Malware
Malware (5)
Threat Actors (1)
MITRE ATT&CK (18)
Vendors (5)
Products (9)
Tools (1)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.