Sonatype Security Research has identified two hijacked npm packages in the React Native ecosystem that receive more than 30,000 downloads collectively per week and were modified to deliver multi-stage malware. Sonatype is tracking the malicious packages as sonatype-2026-001153.
The post Hijacked npm Packages Deliver Malware via Solana, Linked to Glassworm appeared first on Security Boulevard.
Sonatype Security Research Team
Source: Security Boulevard
Source Link: https://securityboulevard.com/2026/03/hijacked-npm-packages-deliver-malware-via-solana-linked-to-glassworm/