Malware & Threats
The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials.
Hi, what are you looking for?
Hackers pushed a poisoned arrayref version that added a dependency to fetch a malicious payload from a remote server.
The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials.
The agency said imports of advanced robots pose cybersecurity and other national security risks.
Dependabot gets a three-day cooldown window before opening pull requests, and PyPI rejects file uploads to releases older than 14 days.
New executive order calls for end-to-end visibility into defense supply chains, including software dependencies, foreign ownership and cyber-related supplier risks.
The British firm has built a collaborative platform to help organizations address supply chain security risks.
A threat actor poisoned several Jscrambler NPM package versions to drop a cross-platform credential stealer.
The PolinRider campaign has compromised more than 100 legitimate open source packages and repositories to deliver a backdoor and information stealer to developers.
Decades-old Bash shell tricks can bypass safeguards in most open source AI coding agents, potentially turning malicious repositories into supply chain attack vectors.
Roughly two dozen companies have notified their customers of the Klue-Salesforce incident impact.
A malicious dependency the attackers added to over 140 Mastra packages fetches a payload targeting cryptocurrency extensions.
HackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk, and Tanium are among the affected Klue customers.
The hackers exfiltrated data from Salesforce instances of Klue customers, such as Huntress and Recorded Future.
Arch Linux suspended account registrations in response to the wave of malicious packages being uploaded to AUR.
By default, npm install will no longer execute scripts from dependencies, unless explicitly allowed.
The most recent variants of the self-propagating attacks are named Miasma and Hades.
CVE Lite CLI is a free, open-source command line tool that scans your projects in seconds and tells you exactly which included packages contain...