Blogs

Threat Alert: Private npm Packages Disclosed via Timing Attacks

Aquasec

We at Aqua Nautilus have discovered that npm’s API allows threat actors to execute a timing attack that can detect whether private packages exist on the package manager.

Visit Site

Blogs Aquasec

BlogsThreat Alert: Tracking Real-World Apache Log4j AttacksAquasec BlogsDeceptive Deprecation: The Truth About npm Deprecated PackagesAquasec BlogsNew npm Flaws Let Attackers Better Target Packages for Account TakeoverAquasec BlogsPowerHell: Active Flaws in PowerShell Gallery Expose Users to AttacksAquasec BlogsReal-world Cyber Attacks Targeting Data Science ToolsAquasec BlogsBlocking Attacks in Runtime with Drift Prevention - AquasecAquasec ResearchA Guide to Extended Threat Detection and Response: What It Is and How to Choose the Best SolutionsCybersecurity Exchange BlogsThis Month in the DuckDB Ecosystem: January 2026Motherduck BlogsHow Layers Slashed Analytics Costs and Gave Every Customer a Private Data WarehouseMotherduck BlogsUnderstanding CSRF attacksVercel ResourcesNEXTJS_MISSING_MODULARIZE_IMPORTSVercel BlogsHow to Protect Your Projects from the Risks of Deprecated npm PackagesSocket NewsWhen "Everything" Becomes Too Much: The npm Package Chaos of 2024Socket BlogsPopular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain AttackSocket BlogsCleaning up import paths in JS/TS packagesSocket BlogsSupply Chain Attack on Axios Pulls Malicious Dependency from npmSocket BlogsSuno Breached via Shai-Hulud Worm, Leaked Code Exposes AI Music ScrapingSocket BlogsIntroducing Data ExportsSocket ResourcesDocumentation - JS Projects Utilizing TypeScriptTypescriptlang BlogsIntroducing Usage Limits for Pulumi NeoPulumi