- Over 70 Malicious npm and VS Code Packages Found Stealing Data and Crypto The Hacker News
- Dozens of malicious packages on NPM collect host and network data BleepingComputer
- Destructive malware available in NPM repo went unnoticed for 2 years Ars Technica
- Hackers Using Weaponized npm Packages to Attack React, Node.js JavaScript Frameworks CybersecurityNews
- New supply chain attack with malicious scripts in npm packages heise online