# package compromise

Published articles for package compromise.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Axios package compromise and remediation steps

DevFeed: [Axios package compromise and remediation steps](<https://devfeed.tech/articles/axios-package-compromise-and-remediation-steps-818.md>)

Original publisher: [Read original article](<https://vercel.com/changelog/axios-package-compromise-and-remediation-steps>)

Author: Vercel Security

Published: 2026-03-31T13:00:00Z

Content type: release

Language: en

Sources: [Vercel News](<https://devfeed.tech/sources/vercel-news.md>)

Topics: [npm](<https://devfeed.tech/topics/npm.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>), [Databases](<https://devfeed.tech/topics/databases.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [axios](<https://devfeed.tech/tags/axios.md>), [dependency](<https://devfeed.tech/tags/dependency.md>), [package-compromise](<https://devfeed.tech/tags/package-compromise.md>), [registry](<https://devfeed.tech/tags/registry.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [tokens](<https://devfeed.tech/tags/tokens.md>), [update](<https://devfeed.tech/tags/update.md>), [vercel](<https://devfeed.tech/tags/vercel.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Vercel describes the compromise of the axios npm package in an active supply chain attack discovered on March 31, 2026. The affected versions are axios@1.14.1 and axios@0.30.4, with plain-crypto-js@4.2.1 also identified in compromised dependency chains. Vercel says its systems, infrastructure, and applications were not affected, and reports that the malicious versions were blocked and unpublished while the latest tag points to axios@1.14.0.

### Source excerpt

The axios npm package was compromised in an active supply chain attack discovered on March 31, 2026. Vercel investigated this issue and implemented remediation actions to protect the platform. No Vercel systems were affected. The npm registry removed the compromised package versions, and the latest tag now points to the safe axios@1.14.0 release. We've blocked outgoing access from our build infrastructure to the Command & Control hostname sfrclak.com. The malicious version of the package has been blocked and unpublished from npm. Vercel's own infrastructure and applications have been unaffected. We recommend checking your supply chain for exposure. Affected versions Projects using axios@1.14.1 or axios@0.30.4 in their build environments are affected by this vulnerability. Check your dependencies and lockfiles for: axios@1.14.1 axios@0.30.4 plain-crypto-js@4.2.1 Resolution If your deployments used the malicious package version listed above in your build environment, take the following actions: Search your lockfiles and node_modules for plain-crypto-js to identify compromised installations Redeploy your project to ensure your build uses a clean version of axios Rotate API keys, database credentials, tokens, and any other sensitive values present in your build environment Review your dependency tree for references to axios@1.14.1 or axios@0.30.4 and update them to axios@1.14.0 Read more

## Announcing Chainguard Libraries for JavaScript: Malware-Resistant Dependencies Built Securely from Source

DevFeed: [Announcing Chainguard Libraries for JavaScript: Malware-Resistant Dependencies Built Securely from Source](<https://devfeed.tech/articles/announcing-chainguard-libraries-for-javascript-malware-resistant-dependencies-built-securely-from-source-12879.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/announcing-chainguard-libraries-for-javascript-malware-resistant-dependencies-built-securely-from-source>)

Published: 2025-09-25T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [npm packages](<https://devfeed.tech/topics/npm-packages.md>), [npm](<https://devfeed.tech/topics/npm.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-libraries-for-javascript](<https://devfeed.tech/tags/chainguard-libraries-for-javascript.md>), [javacript](<https://devfeed.tech/tags/javacript.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [language-library-security](<https://devfeed.tech/tags/language-library-security.md>), [malware](<https://devfeed.tech/tags/malware.md>), [npm](<https://devfeed.tech/tags/npm.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [package-compromise](<https://devfeed.tech/tags/package-compromise.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [shai-hulud](<https://devfeed.tech/tags/shai-hulud.md>), [slsa](<https://devfeed.tech/tags/slsa.md>)

### AI overview

Chainguard announces Chainguard Libraries for JavaScript, a source of trusted language-dependency builds intended to protect developers and organizations from compromised packages, malicious updates, and registry-based attacks. The libraries are built from source on hardened SLSA L2 infrastructure, include provenance, and are designed to fit existing developer workflows.

### Source excerpt

Chainguard Libraries for JavaScript is designed to protect developers and organizations from compromised packages, malicious updates, and registry-based attacks.

## Zero-day Extensive NPM Package Compromise - Shai Hulud Supply Chain Attack

DevFeed: [Zero-day Extensive NPM Package Compromise - Shai Hulud Supply Chain Attack](<https://devfeed.tech/articles/zero-day-extensive-npm-package-compromise-shai-hulud-supply-chain-attack-7902.md>)

Original publisher: [Read original article](<https://snyk.io/blog/embedded-malicious-code-in-tinycolor-and-ngx-bootstrap-releases-on-npm/>)

Author: Brian Clark

Published: 2025-09-15T11:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [npm packages](<https://devfeed.tech/topics/npm-packages.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Angular](<https://devfeed.tech/topics/angular.md>), [Bootstrap](<https://devfeed.tech/topics/bootstrap.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Security](<https://devfeed.tech/topics/security.md>), [data](<https://devfeed.tech/topics/data.md>), [Front end](<https://devfeed.tech/topics/frontend.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [angular](<https://devfeed.tech/tags/angular.md>), [api-keys](<https://devfeed.tech/tags/api-keys.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [incident](<https://devfeed.tech/tags/incident.md>), [malware](<https://devfeed.tech/tags/malware.md>), [npm](<https://devfeed.tech/tags/npm.md>), [package-compromise](<https://devfeed.tech/tags/package-compromise.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [shai-hulud](<https://devfeed.tech/tags/shai-hulud.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [worm](<https://devfeed.tech/tags/worm.md>)

### AI overview

This article reports the Shai-Hulud supply chain attack, in which malicious versions of ngx-bootstrap and other npm packages embedded malware to harvest developer tokens, cloud credentials, API keys, and other secrets. The malware exfiltrated data through webhooks and public GitHub repositories, targeted CI/CD environments through GitHub Actions, and spread across hundreds of compromised packages. The article recommends treating affected systems as compromised, removing the packages, rotating secrets from a trusted machine, and investigating for lateral movement.

### Source excerpt

A supply chain attack hit the ngx-bootstrap npm package, embedding malware to steal developer credentials. See affected versions (e.g., 20.0.4-6, 19.0.3) and our playbook to contain the threat and rotate compromised secrets.

## Lottie Player npm package compromised for crypto wallet theft

DevFeed: [Lottie Player npm package compromised for crypto wallet theft](<https://devfeed.tech/articles/lottie-player-npm-package-compromised-for-crypto-wallet-theft-8007.md>)

Original publisher: [Read original article](<https://snyk.io/blog/lottie-player-npm-package-compromised-crypto-wallet-theft/>)

Author: Liran Tal

Published: 2024-10-31T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [npm](<https://devfeed.tech/topics/npm.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>), [snyk](<https://devfeed.tech/topics/snyk.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cli](<https://devfeed.tech/tags/cli.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [crypto](<https://devfeed.tech/tags/crypto.md>), [dependency](<https://devfeed.tech/tags/dependency.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [incident](<https://devfeed.tech/tags/incident.md>), [npm](<https://devfeed.tech/tags/npm.md>), [package-compromise](<https://devfeed.tech/tags/package-compromise.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The @lottiefiles/lottie-player npm package was compromised after an npm registry publishing token was exposed. Malicious code in versions 2.0.5, 2.0.6, and 2.0.7 attempted to prompt users to connect cryptocurrency wallets. Those versions were removed, and version 2.0.8 restored the safe project code. The article explains how to use Snyk Dependency Reports and the Snyk CLI to identify affected projects and vulnerable dependencies.

### Source excerpt

On October 31st, 2024, another package compromise and cryptocurrency hijack story unfolded for a popular npm package. Scan open source dependencies and container images in the CLI or your SCM with Snyk to determine if you're using one of the vulnerable versions of lottie-player, and potentially uncover any other security vulnerabilities you may have in your projects.