Stop Malicious Code. Not Engineers. AI-powered detection of malicious open-source packages in package manages such as npm and PyPI. ossprey.com/

London
Ossprey Security retweeted
Meet @osspreysecurity ! Ossprey is the security tool built for engineering-led companies who depend on open source and can’t afford to slow down. You can learn more here: ossprey.com/?BSC26
2
8
290
We are currently tracking the following NPM user publishing EtherHiding malware. npmjs.com/~anhn One package named anhn-cli and several others scoped to @wizloft The contract address is associated with previous DPRK related malware we have seen in the past weeks 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a
1
52
Recently we have seen DPRK malware move away from jsonkeeper following our recent takedown action with the host. New malware appears to be abusing tiiny.host express-chai 3.7.8 https://gray-dyane-31.tiiny[.]site/index.json
2
6
996
We have noticed some more movement from the current DPRK EtherHiding/NullReceiver campaign on NPM. Using the same C2 that has been covered previously 166.88.134[.]62 Wallet remains active etherscan.io/address/0xa322E… @voxepay/checkout v0.5.19 @zahlen/checkout-angular v0.1.4 @zahlen/checkout v0.2.2 simplipayng v1.0.8 @vboxdev/common v1.0.73 @nasddatax/common v1.0.21 @rentwise/common v1.0.36 @nasdtickets/common v1.0.23
1
4
777
The on-going shai hulud attack is spreading significantly. Hundreds of packages scoped to @servicetitan are now compromised too. We will be sharing an analysis and remediation advice shortly for all affected developers
91
Ossprey Security is currently tracking the compromise of several popular packages, with over 160 million weekly downloads combined. More information coming soon keyv v6.0.0 @cacheable/net v2.1.1 @cacheable/node-cache v3.1.2 cacheable v2.5.1 @cacheable/memory v2.2.1 file-entry-cache v11.1.6 @cacheable/utils v2.5.1 ecto v5.0.1
2
3
149
Ossprey Security retweeted
10 pre-seed raises you probably missed this week Bluecore Energy - nuclear barges ($10M) @Epic_Markets - CFD brokerage ($10M) ORiS - satellite laser recharging ($5.1M) Coverwatch - flat-fee insurance ($4.5M) Cast Insights - speech intelligence ($4.5M) Immitra Bio - in-vivo gene editing ($3M) @osspreysecurity - supply-chain security ($2.7M) @superstatsport - sports analytics ($2.3M) @EELITechnology - lithium from brines ($2M) @ChatFeaturedAI - answer-engine SEO ($2M) A thread…
1
3
17
1,677
Ossprey Security retweeted
Tech News of the Week: (This is for informational purposes only, and in no particular order.) 1) Prodlane: Female-led Prodlane Snaps €4M to Build an AI Assistant for Technical Teams. Source: techfundingnews.com/maia-pro… 2) deltaVision: deltaVision Raises €10.2M to Accelerate Orbital Refuelling Technology. Source: tech.eu/2026/07/21/deltavisi… 3) Circular Materials: Circular Materials Secures €11.8M to Scale Critical Raw Material Recovery Technology. Source: tech.eu/2026/07/21/circular-… 4) 30 Sundays: Traveltech Startup 30 Sundays Raises ₹61 Cr To Expand AI-Powered Holiday Planning. Source: inc42.com/buzz/traveltech-st… 5) Hilo @hilo_health: Hilo Raises $19M Series B Extension for Fitbit-Style Blood Pressure Health System: Can it Replace 145-Year-Old Cuff Technology? Source: techfundingnews.com/hilo-rai… 6) Cascade: AI Engineering Project Predictor Startup Cascade Wins Backing from a16z Accelerator. Source: tech.eu/2026/07/21/ai-engine… 7) Dimension Capital: Dimension Capital’s $800M Third Fund Shows the Intersection of Science and Compute is Booming. Source: techcrunch.com/2026/07/21/di… 8) Omio @omioglobal: Harvard Graduate with Indian Roots Secures $10M for Omio to Bring AI Multimodal Travel to Japan and Southeast Asia. Source: techfundingnews.com/harvard-… 9) Ossprey: Ossprey Secures $2.65M to Stop Software Supply Chain Attacks. Source: tech.eu/2026/07/22/ossprey-s… 10) Deutsche Sanierungsberatung: Berlin’s Deutsche Sanierungsberatung Raises Over €10 Million to Accelerate Climate-Neutral Home Renovations. Source: eu-startups.com/2026/07/berl…
1
1
1
85
🚨Ossprey has detected two malicious npm packages - `aurelia-type@0.5.1` and `selparsecss-selector@2.1.0`. Dropping IPFS-hosted payloads on macOS and Windows. RC4-obfuscated dropper installs `com.apple.updatesystem` LaunchAgent or Win registry persistence. Remove immediately.
1
4
271
Miasma is back. M-RED-TEAM claims the compromise of 5 asyncapi scoped packages. Our breakdown, TTPs, IOCs and analysis here. ossprey.com/blog/asyncapi-np…
1
4
66
Ossprey has seen 22 NPM packages scoped to marketfront delivering a secret / environment stealer similar to another campaign we covered a while back. ossprey.com/blog/moika-tech-… The marketfront packages are using the following C2 for exfil. C2: https://pik-libs[.]ru/api/v1/events
3
390
Today, Ossprey Security detected 4 NPM packages being published by the DPRK. This is the story of how Ossprey Security detected and disrupted a massive on-going DPRK malware campaign. ossprey.com/blog/how-ossprey…
1
3
46
The zenith-utils@12.0.14 This package was rapidly removed from npmjs, but the C2 may be re-used, we recommend pre-emptively blocking 138[.]201[.]140[.]23, and blocking jsonkeeper[.]com, as although this is safe, it's increasingly being used to exfil data.
1
29
🚨Ossprey detected zenith-utils@12.0.14, a malicious npm package that installs a remote payload from jsonkeeper, hijacks MetaMask in every Chrome profile, and exfiltrates wallet extension data and seed files to 138[.]201[.]140[.]23. Remove it and rotate credentials immediately. #supplychainsecurity
1
1
68
Process 3: file-system crawl. Walks the home directory and uploads *.env*, *seed*, *mnemonic*, *wallet*, *.pdf, *.json matches to port 4556.
1
21
Process 4 is the most destructive: downloads a trojanized MetaMask build from port 4553, extracts it, patches ui-20.js, rewrites Chrome Secure Preferences, and kills/restarts Chrome. Replacing the legitimate extension with an attacker-controlled wallet UI
29