⤷ Title: Vitest RCE Vulnerability (CVSS 9.8): Public PoC Disclosed for Testing Tool With 57M Weekly Downloads (CVE-2026-53633)
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 02:12:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Browser Mode #CDP #CVE_2026_53633 #npm #rce #Supply Chain #Vite #Vitest
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 02:12:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Browser Mode #CDP #CVE_2026_53633 #npm #rce #Supply Chain #Vite #Vitest
Daily CyberSecurity
Vitest RCE Vulnerability (CVSS 9.8): Public PoC Disclosed for Testing Tool With 57M Weekly Downloads (CVE-2026-53633)
A critical Vitest RCE vulnerability (CVE-2026-53633, CVSS 9.8) has public PoC code. Browser Mode flaw enables config overwrite and remote code execution.
⤷ Title: Mastra Supply Chain Attack Compromises 140+ npm Packages
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 08:04:43 +0000
════════════════════════
⌗ Tags: #Malware #easy_day_js #Infostealer #Mastra #npm #Socket #supply chain attack #Typosquatting
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 08:04:43 +0000
════════════════════════
⌗ Tags: #Malware #easy_day_js #Infostealer #Mastra #npm #Socket #supply chain attack #Typosquatting
Daily CyberSecurity
Mastra Supply Chain Attack Compromises 140+ npm Packages
A Mastra supply chain attack compromised 140+ npm packages, using the typosquatted easy-day-js dependency to drop a crypto-stealing infostealer.
⤷ Title: i18next Prototype Pollution Flaw (CVSS 9.1) Threatens 1M+ Weekly Downloads
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 01:00:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_48713 #CVE_2026_48714 #i18next #i18next_fs_backend #Node.js Security #npm Vulnerability #Prototype Pollution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 01:00:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_48713 #CVE_2026_48714 #i18next #i18next_fs_backend #Node.js Security #npm Vulnerability #Prototype Pollution
Daily CyberSecurity
i18next Prototype Pollution Flaw (CVSS 9.1) Threatens 1M+ Weekly Downloads
CVE-2026-48713 exposes i18next prototype pollution in i18next-fs-backend, a CVSS 9.1 flaw threatening 1M+ weekly downloads. Update to 2.6.6 now.
⤷ Title: NPM Package Tests AI Malware Scanner Evasion
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sun, 21 Jun 2026 07:30:50 +0000
════════════════════════
⌗ Tags: #Malware #AI Malware #Cyber Security #npm Security #Prompt injection
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sun, 21 Jun 2026 07:30:50 +0000
════════════════════════
⌗ Tags: #Malware #AI Malware #Cyber Security #npm Security #Prompt injection
Daily CyberSecurity
NPM Package Tests AI Malware Scanner Evasion
A new npm package uses prompt injection and token flooding for AI malware scanner evasion. Discover how attackers disrupt AI-assisted malware review.
⤷ Title: Four undici Vulnerabilities Affect a Package With 133M Weekly Downloads
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 22 Jun 2026 02:00:04 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_6734 #CVE_2026_9697 #nodejs #npm #SOCKS5 #TLS Bypass #undici #WebSocket
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 22 Jun 2026 02:00:04 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_6734 #CVE_2026_9697 #nodejs #npm #SOCKS5 #TLS Bypass #undici #WebSocket
Daily CyberSecurity
Four undici Vulnerabilities Affect a Package With 133M Weekly Downloads
Four undici vulnerabilities (CVE-2026-6734, CVE-2026-9697) affect the Node.js HTTP client, which sees 133M weekly downloads. Update undici now.
⤷ Title: Fake npm Packages Impersonate PostCSS Tool to Steal Chrome Passwords
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 24 Jun 2026 13:26:36 +0000
════════════════════════
⌗ Tags: #Security #Malware #Chrome #Cyber Attack #Cybersecurity #JFrog #NPM #Password #PostCSS #RAT #Scam #security #Windows
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 24 Jun 2026 13:26:36 +0000
════════════════════════
⌗ Tags: #Security #Malware #Chrome #Cyber Attack #Cybersecurity #JFrog #NPM #Password #PostCSS #RAT #Scam #security #Windows
Hackread
Fake npm Packages Impersonate PostCSS Tool to Steal Chrome Passwords
JFrog warns of malicious npm packages that mimic PostCSS tooling, drop a Windows RAT, and target Chrome-stored passwords through a staged infection setup route.
⤷ Title: Mastra npm Supply Chain Attack Poisons 140+ AI Packages
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 06:07:30 +0000
════════════════════════
⌗ Tags: #Malware #easy_day_js #Infostealer #Mastra #npm #Sapphire Sleet #supply chain attack
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 06:07:30 +0000
════════════════════════
⌗ Tags: #Malware #easy_day_js #Infostealer #Mastra #npm #Sapphire Sleet #supply chain attack
Information Security News
Mastra npm Supply Chain Attack Poisons 140+ AI Packages
Attackers infected more than 140 packages from the Mastra AI ecosystem through npm. The malicious code ran right after npm install or npm update. So the infection could reach developer workstation…
⤷ Title: Lazarus-Linked npm Malware Masquerades as Rollup Polyfills
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 09:22:14 +0000
════════════════════════
⌗ Tags: #Cybercriminals #crypto wallet theft #JFrog #Lazarus #malicious npm packages #North Korea #npm malware #Rollup polyfill #supply chain attack
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 09:22:14 +0000
════════════════════════
⌗ Tags: #Cybercriminals #crypto wallet theft #JFrog #Lazarus #malicious npm packages #North Korea #npm malware #Rollup polyfill #supply chain attack
Daily CyberSecurity
Lazarus-Linked npm Malware Masquerades as Rollup Polyfills
At a glance Actor Suspected North Korean Lazarus-linked group (attribution by TTP similarity) Activity npm supply chain attack using lookalike Rollup polyfill packages Targets JavaScript developer…
⤷ Title: PolinRider Supply Chain Attack Spans npm, Go, Chrome
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 08:38:34 +0000
════════════════════════
⌗ Tags: #Malware #Contagious Interview #Famous Chollima #Go Modules Security #North Korea Hackers #NPM Malware #PolinRider #supply chain attack
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 08:38:34 +0000
════════════════════════
⌗ Tags: #Malware #Contagious Interview #Famous Chollima #Go Modules Security #North Korea Hackers #NPM Malware #PolinRider #supply chain attack
Information Security News
PolinRider Supply Chain Attack Spans npm, Go, Chrome
PolinRider is no longer a story about a handful of malicious npm packages. Researchers at Socket uncovered 162 malicious release artifacts spread across 108 packages and browser extensions. The ca…
⤷ Title: North Korea-Linked PolinRider Supply Chain Attack Expands Across Open Source
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 07:53:40 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Contagious Interview #DEV#POPPER #Famous Chollima #North Korean hackers #npm #Packagist #PolinRider #Socket #supply chain attack
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 07:53:40 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Contagious Interview #DEV#POPPER #Famous Chollima #North Korean hackers #npm #Packagist #PolinRider #Socket #supply chain attack
Daily CyberSecurity
North Korea-Linked PolinRider Supply Chain Attack Expands Across Open Source
At a Glance Actor / group Suspected North Korean actors in the Contagious Interview / Famous Chollima cluster (Socket assessment) Activity type Open-source supply chain campaign; hidden JavaScript…