Close Menu
TechurzTechurz
    What's Hot

    Meet Wrinkles, an AI app that uncovers the hidden stories of the places around you

    August 4, 2026

    Take an extra $100 off your TechCrunch Disrupt 2026 pass: This week only!

    August 4, 2026

    Bending Spoons to buy Airtable for $1.28B

    August 4, 2026
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Tech Pulse
    • Meet Wrinkles, an AI app that uncovers the hidden stories of the places around you
    • Take an extra $100 off your TechCrunch Disrupt 2026 pass: This week only!
    • Bending Spoons to buy Airtable for $1.28B
    • Base Power raises another $1B to save the grid using backyard batteries
    • Design Arena creators raise $7.9 million to bring taste to AI models
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    TechurzTechurz
    • Home
    • Tech Pulse
    • Future Tech
    • AI Systems
    • Cyber Reality
    • Disruption Lab
    • Signals
    TechurzTechurz
    Home - Cyber Reality - Malicious packages in npm evade dependency detection through invisible URL links: Report
    Cyber Reality

    Malicious packages in npm evade dependency detection through invisible URL links: Report

    TechurzBy TechurzOctober 31, 2025Updated:May 10, 2026No Comments1 Min Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Hacker with malware code in computer screen. Cybersecurity, privacy or cyber attack. Programmer or fraud criminal writing virus software. Online firewall and privacy crime. Web data engineer.
    Share
    Facebook Twitter LinkedIn Pinterest Email


    At some point, npm leadership either discovered this campaign on its own or was alerted by other researchers, because in August, 21 packages were removed from the repository. However, after September, 80 additional packages were uploaded. All, Koi Security believes, were clearly controlled by the same person.

    β€˜Disastrous’ flaw in npm

    This is a β€œdisastrous” systemic design flaw in npm’s dependency management functionality, Tanya Janca, head of Canadian secure coding training firm She Hacks Purple Consulting, told CSO. The lack of validation for dependency URLs bypasses the trust boundary for the Node.js software supply chain, she said.

    Few programming languages allow dependencies to be specified via URLs, and even most of those that do have package managers that block this feature due to security concerns, she said. For instance, she pointed out, it’s allowed in Python, but the open source Python Package Index repository of packages (PyPI) blocks this functionality.

    dependency detection evade invisible links Malicious npm packages Report URL
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleThis simple Pixel update finally makes my Android calls as nice as iPhone’s
    Next Article New “Brash” Exploit Crashes Chromium Browsers Instantly with a Single Malicious URL
    Techurz
    • Website

    Related Posts

    Opinion

    Superhuman acquires AI detection startup GPTZero

    June 23, 2026
    Cyber Reality

    Digital Identity Protection: 7 Hidden Risks Most Users Miss

    May 25, 2026
    Cyber Reality

    Neural Data Policy: 7 Risks That Brain Privacy Laws Miss

    May 25, 2026
    Add A Comment
    Latest Tech Pulse

    College social app Fizz expands into grocery delivery

    September 3, 20252,290

    12 Father’s Day E-Card Sites That Are Actually Good

    June 4, 202523

    SolarSquare in talks to raise up to $60M as India’s rooftop solar market draws major VC interest

    May 23, 202622
    Stay In Touch
    • YouTube
    • WhatsApp
    • Twitter
    • Pinterest
    • LinkedIn

    Techurz helps readers stay ahead of digital change with clear, practical, future focused technology intelligence written today,searched tomorrow.

    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Company
    • About Us
    • Contact Us
    • Our Authors / Editorial Team
    • Write For Us
    • Advertise
    Policy
    • Editorial Policy
    • Privacy Policy
    • Terms and Conditions
    • Affiliate Disclosure
    • Cookie Policy
    • Disclaimer
    • DMCA
    Explore
    • AI Systems
    • Cyber Reality
    • Future Tech
    • Disruption Lab
    • Signals
    • Tech Pulse
    • Sitemap

    Join the Techurz Brief

    The future does not arrive suddenly.
    Stay ahead with fast, sharp tech signals.

    Type above and press Enter to search. Press Esc to cancel.