Config Files That Run Code: Supply Chain Security Blindspot

a fake bug fix PR hid a credential stealer in astro.config.mjs that used blockchain to receive commands

someone actually leaked the Miasma supply chain attack toolkit source code on github

@redhat-cloud-services publish pipeline is compromised today and shipped a signed, trusted, malicious npm package

Mass NPM Supply Chain Attack Hits TanStack, Mistral AI, and 170 Packages

Mini Shai-Hulud Strikes Again: 314 npm Packages Compromised

Megalodon: Mass GitHub Repo Backdooring via CI Workflows

Someone hid a full RAT inside a fake npm package and exfiltrated victim data to HuggingFace

Someone compromised SAP's npm packages and used the CI pipeline against itself

@fairwords npm packages compromised by a self-propagating credential worm - steals tokens, infects other packages you own, then crosses to PyPI

Someone is actively publishing malicious packages targeting the Strapi plugin ecosystem right now

Dependency cooldown using the publish age as a signal for package resolution

axios 1.14.1 and 0.30.4 on npm are compromised - dependency injection via stolen maintainer account

TeamPCP strikes again - telnyx 4.87.1 and 4.87.2 on PyPI are malicious

Malicious litellm 1.82.8: Credential Theft and Persistent Backdoor

Using CEL's now() to enforce dependency cooldown periods - block packages published in the last N hours

Agent Skills Threat Model

Reverse Engineering Malicious Visual Studio Code Extension DarkGPT

React RCE vul technical blog

Shai-Hulud Second Coming: Software Supply Chain Attack Exposing Code and Harvesting Credentials

Curious Case of Embedded Executable in a Newly Introduced Go Transitive Dependency

Self-replicating worm like behaviour in latest npm Supply Chain Attack

TensorFlow.js Typosquatting Attack: Malicious Package Targeting AI/ML Developers

eslint-config-prettier Compromised: How npm Package with 30 Million Downloads Spread Malware

Malicious npm eslint-config-airbnb-compat Package Hides Detection with Payload Splitting

Malicious npm Package Impersonating Popular Express Cookie Parser