WhisperX tag archive

#npm packages

This page collects WhisperX intelligence signals tagged #npm packages. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-05-13 13:18:37 · Mastodon:mastodon.social:#cybersecurity

1. Typosquatting npm Packages Exploit Claude Code SessionStart Hooks to Deploy Persistent Developer Backdoors

A newly identified supply chain attack is targeting software developers through typosquatting npm packages that weaponize Claude Code's SessionStart hooks to establish persistent backdoors on infected systems. The campaign delivers a statically linked, UPX-compressed ELF binary that activates during package installatio...