Safeguard
Tag

npm-security

Safeguard articles tagged "npm-security" — guides, analysis, and best practices for software supply chain and application security.

100 articles

Security News

postmark-mcp: The First Confirmed Malicious MCP Server Found in the Wild

A single added line of code in a compromised npm package silently BCC'd every outgoing email to an attacker. Snyk's disclosure marks the first real, deployed malicious MCP server, not a proof of concept.

Sep 16, 20266 min read
Security News

Shai-Hulud: The Self-Replicating npm Worm That Also Exposed AI Tooling's Dependency Risk

CISA flagged a supply-chain worm that used each compromised npm package to automatically publish more compromised packages, poisoning 500-plus libraries across the ecosystem AI/ML tooling shares.

Sep 16, 20266 min read
Industry Analysis

Five Numbers From the CrowdStrike 2026 Threat Hunting Report That Should Change Your Roadmap

87% of software registry threats were malicious npm packages. 88% of exploitation with a public PoC happened inside 48 hours. Device code phishing rose 15x. Five numbers, five pieces of work.

Aug 6, 20266 min read
Vulnerability Analysis

What is prototype pollution and why it keeps recurring in npm packages

Prototype pollution has hit lodash, jQuery, minimist, hoek, and immer since 2018. Here's how the bug works and why it keeps coming back in npm.

Aug 4, 20266 min read
Vulnerability Analysis

Typosquatting in open source package registries explained

Typosquatting hides malware behind a one-character package name typo. Learn how it works, real incidents, and how to detect it before your build runs.

Jul 31, 20267 min read
Vulnerability Analysis

How to detect malicious npm packages

Real npm supply chain attacks — event-stream, ua-parser-js, node-ipc, and the 2025 chalk/debug breach — show how to spot and stop malicious packages.

Jul 31, 20266 min read
Open Source Security

node-tar Arbitrary File Write via Symlink Extraction (CVE...

CVE-2021-32803 allows crafted symlinks in tar archives to make node-tar write files outside the extraction directory via malicious npm packages.

Jul 28, 20267 min read
Open Source Security

node-tar Second Bypass Enabling Arbitrary File Write (CVE...

CVE-2021-32804 let crafted tar archives bypass node-tar path sanitization, enabling arbitrary file writes during npm package extraction.

Jul 28, 20267 min read
Open Source Security

node-tar Windows-Specific Path Traversal Bypass (CVE-2021...

CVE-2021-37712 let malicious tar archives bypass node-tar's symlink protections on Windows via junctions, enabling path traversal during npm installs. Here's what to patch.

Jul 28, 20268 min read
Open Source Security

minimist Prototype Pollution and Its Ripple Effect Across...

CVE-2020-7598 is a prototype pollution bug in minimist that let attackers taint Object.prototype, rippling through thousands of npm dependents.

Jul 28, 20268 min read
Open Source Security

lodash zipObjectDeep Prototype Pollution (CVE-2020-8203)

CVE-2020-8203 is a prototype pollution flaw in lodash's zipObjectDeep, affecting versions before 4.17.19. Here's the impact, timeline, and how to remediate it.

Jul 28, 20268 min read
Open Source Security

The coa and rc npm Maintainer Account Hijack Incident

How the coa and rc npm hijack let attackers seize maintainer accounts on two packages with 20M+ weekly downloads to push Windows password-stealing malware.

Jul 27, 20266 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.