October 24, 2021 Node poisoning: hijacked package delivers coin miner and credential-stealing backdoor A hacked NPM account was used to deliver Linux and Windows Monero miners and Windows credential-stealing malware along with a popular node.js library. SophosLabs UncutThreat Research
September 06, 2021 Poisoned proxy PACs! The NPM package with a network-wide security hole… 3,000,000 downloads a week... if only they'd read the fastidious manual! Naked Security
November 28, 2018 JavaScript library used for sneak attack on Copay Bitcoin wallet A mystery payload sneaked into a hugely popular JavaScript library was part of a plot to ransack Bitcoins from BitPay’s Copay mobile cryptocoin wallet, it has been alleged. Naked Security