New Supply Chain Malware Operation Hits npm and PyPI Ecosystems Targeting Millions Globally

Researchers studying cybersecurity have discovered a supply chain attack that uses more than a dozen GlueStack-related items to spread malware.

According to Aikido Security, which told The Hacker News that these packages together account for about 1 million downloads every week, the virus was introduced by altering “lib/commonjs/index.js,” which enables an attacker to execute shell commands, capture screenshots, and upload data to compromised computers.

Numerous subsequent activities, such as mining bitcoin, stealing private data, and even stopping services, could be carried out using the unauthorized access. According to Aikido, the first package breach was discovered at 9:33 p.m. GMT on June 6, 2025.

The affected versions and a list of the impacted packages read more about New Supply Chain Malware Operation Hits npm and PyPI Ecosystems Targeting Millions Globally.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *