PackageGate bugs let attackers bypass protections in NPM, PNPM, VLT, and Bun
ID: dc2c472e-a13b-5e1b-bcd7-0254c87ea0a4
STIX ID: report--dc2c472e-a13b-5e1b-bcd7-0254c87ea0a4
Feed Name: Security Affairs
Threat Score
Koi researchers disclosed “PackageGate,” a set of six zero-day flaws in npm, pnpm, vlt, and Bun that allow attackers to bypass lifecycle-script blocking and lockfile integrity (e.g., malicious .npmrc replacing git, prepare scripts during git fetches, tarball path traversal, and package name trust abuses), enabling supply-chain RCE; pnpm, vlt, and Bun patched the issues while npm dismissed the report, prompting public disclosure and recommendations to harden workflows.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
