CyberMaterial

CyberMaterial

Alerts

Malicious Npm Packages Steal Secrets

Feb 23, 2026
∙ Paid

Researchers have identified a new supply chain worm campaign dubbed SANDWORM_MODE that uses 19 malicious npm packages to steal credentials and cryptocurrency keys. The malware spreads by hijacking de…

User's avatar

Continue reading this post for free, courtesy of CyberMaterial.

Or purchase a paid subscription.
© 2026 CyberMaterial · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture