A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems ...
keyv npm supply chain attack on August 4, 2026 let the Shai-Hulud worm compromise 400-plus packages and more than two billion ...
More than 400 NPM packages have been infected with the Mini Shai-Hulud worm in the ChainDrop supply chain attack.
Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly ...
The Shai Hulud variant’s blast radius includes several highly popular packages thus far.. Security teams are urged to perform ...
A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes malicious infrastructure harder to detect while ...
Gemini CLI and Claude Code flaws let untrusted GitHub input reach CI workflows, including host command execution and API key ...
A Keyv-linked npm worm poisoned 353 versions across 79 package names, stealing developer and CI credentials while repository ...
Latest update to Microsoft’s code editor improves dictation, introduces side chats, and adds support for comments to provide ...
Typosquatting on popular AI services Paperclip and Browser Use, the malicious skills cracked skills.sh’s trending list, ...
Upwind identified a malicious release of [email protected] that harvested AWS, GitHub, and npm credentials via a hidden preinstall script. With 154 million weekly downloads, the compromise had ecosystem-wide ...
A single-author repo of instruction files, not code, Ponytail passed 44,000 GitHub stars in nine days by making coding agents ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results