Cloud Threat Landscape
  • Incidents
  • Actors
  • Techniques
  • Defenses
  • Tools
  • Targeted Technologies
  • Posters & Newspapers
  • About
  • RSS
  • STIX
  • Back to wiz.io

Made with 💙 by Wiz

Last Updated: April 3, 2025

Cloud Threat Landscape
/Targeted Technologies
Targeted Technologies
/
npm

npm

Prevalence (%)

0.59

Incidents
fsevents supply chain attackRspack supply chain attackSupply Chain Compromise of rand-user-agent: Obfuscated RAT with C2 Communication and File ExfiltrationSolana web3.js Supply Chain AttackNPM Supply Chain Attack Compromises 16 Popular React Native and GlueStack PackagesSupply Chain Attack on npm Packages via Maintainer PhishingNx Package Supply Chain Compromise Delivers Data-Stealing MalwareGhostAction campaignQix npm package supply chain compromiseShai-Hulud: Ongoing Package Supply Chain Compromise Delivering Data-Stealing MalwareShai-Hulud 2.0 Supply Chain AttackSANDWORM_MODE: Typosquatted npm Packages Used to Hijack CI WorkflowsExploitation of S1ngularity-exposed cloud keys for lateral movement
Last edited
May 21, 2024 2:18 PM
CISA KEV
Metasploit
Nuclei
No. Incidents
1
Techniques
Package dependency confusionSlopsquatting