Malicious PyPI and npm Packages Discovered Exploiting Dependencies in Supply Chain Attacks
- Posted on August 18, 2025
- By The Hacker News
- 1 Views

Malicious PyPI and npm Packages Discovered Exploiting Dependencies in Supply Chain Attacks

PyPI malware termncolor and colorinal downloaded 884 times exploit DLL side-loading, persistence, and C2 communication.