News and Notes from the Makers of Nexus | Sonatype Blog | Sonatype Research Team

Posts by Sonatype Research Team

[Q2 2026 Open Source Malware Index: Attackers Abuse Developer Trust](/content/blog/q2-2026-open-source-malware-index-attackers-abuse-developer-trust "Internal link to Q2 2026 Open Source Malware Index: Attackers Abuse Developer Trust resource"/index.html)

Read More

[Miasma Returns: Leo Platform Compromise Shows Why Package Detection Needs Context](/content/blog/miasma-returns-leo-platform-compromise-in-npm "Internal link to Miasma Returns: Leo Platform Compromise Shows Why Package Detection Needs Context resource"/index.html)

Read More

[easy-day-js npm Campaign Targets Mastra as Malicious Dependency Attacks Grow](/content/blog/easy-day-js-targets-mastra-dependency-attacks-grow "Internal link to easy-day-js npm Campaign Targets Mastra as Malicious Dependency Attacks Grow resource"/index.html)

Read More

[Atomic Arch: Attackers Hijack Trusted AUR Packages to Deliver Rootkit-Like Malware](/content/blog/atomic-arch-npm-campaign-adds-malicious-dependency "Internal link to Atomic Arch: Attackers Hijack Trusted AUR Packages to Deliver Rootkit-Like Malware resource"/index.html)

Read More

[New Shai-Hulud Miasma Wave Hits Hundreds of npm Packages](/content/blog/new-shai-hulud-miasma-wave-hits-hundreds-of-npm-packages "Internal link to New Shai-Hulud Miasma Wave Hits Hundreds of npm Packages resource"/index.html)

Read More

[Lazarus Group's Latest: Brandjacking Campaign on npm](/content/blog/lazarus-groups-latest-brandjacking-campaign-on-npm "Internal link to Lazarus Group's Latest: Brandjacking Campaign on npm resource"/index.html)

Read More

[Red Hat Cloud Services npm Packages Hijacked](/content/blog/red-hat-cloud-services-npm-packages-hijacked "Internal link to Red Hat Cloud Services npm Packages Hijacked resource"/index.html)

Read More

[Inside a 176-Package npm Campaign Built to Beat Your Internal Dependencies](/content/blog/inside-a-176-package-npm-campaign-built-to-beat-your-internal-dependencies "Internal link to Inside a 176-Package npm Campaign Built to Beat Your Internal Dependencies resource"/index.html)

Read More

[Hijacked npm Package Attempts to Deliver PolinRider-Linked RAT](/content/blog/hijacked-npm-package-attempts-to-deliver-polinrider-linked-rat "Internal link to Hijacked npm Package Attempts to Deliver PolinRider-Linked RAT resource"/index.html)

Read More

[Shai-Hulud Is Back, and npm Maintainer Accounts Are Still the Soft Target](/content/blog/shai-hulud-is-back-maintainers-the-target "Internal link to Shai-Hulud Is Back, and npm Maintainer Accounts Are Still the Soft Target resource"/index.html)

Read More

[PyTorch Lightning Compromised With Two Malicious Package Versions Published](/content/blog/malicious-pytorch-lightning-packages-found-on-pypi "Internal link to PyTorch Lightning Compromised With Two Malicious Package Versions Published resource"/index.html)

Read More

[Self-Propagating npm Malware Turns Trusted Packages Into Attack Paths](/content/blog/self-propagating-npm-malware-turns-trusted-packages-into-attack-paths "Internal link to Self-Propagating npm Malware Turns Trusted Packages Into Attack Paths resource"/index.html)

Read More