logo

PackageGate bugs let attackers bypass protections in NPM, PNPM, VLT, and Bun

ID: dc2c472e-a13b-5e1b-bcd7-0254c87ea0a4

STIX ID: report--dc2c472e-a13b-5e1b-bcd7-0254c87ea0a4

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-01-28

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Koi researchers disclosed “PackageGate,” a set of six zero-day flaws in npm, pnpm, vlt, and Bun that allow attackers to bypass lifecycle-script blocking and lockfile integrity (e.g., malicious .npmrc replacing git, prepare scripts during git fetches, tarball path traversal, and package name trust abuses), enabling supply-chain RCE; pnpm, vlt, and Bun patched the issues while npm dismissed the report, prompting public disclosure and recommendations to harden workflows.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.