CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Risky Bulletin: Damaging worm rips through npm ecosystem

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6539

As cited

Copy frozen at (site build).

Risky Bulletin: Damaging worm rips through npm ecosystem

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

breaches incidents

Risky Bulletin: Damaging worm rips through npm ecosystem

A worm spread through the npm package repository, representing another major supply chain attack on the JavaScript ecosystem. Separately, RubyGems disabled new account sign-ups following an attack targeting staff, Instructure paid a ransom demand, and the Gentlemen ransomware group itself fell victim to a breach.

Why it matters: Developers relying on npm packages face ongoing risks from malicious code in the supply chain; RubyGems users and maintainers should monitor for account compromise during the sign-up suspension; Instructure customers should assess ransomware exposure if their data was accessed before payment.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary