Red Hat hit by npm supply‑chain attack - here's how to stay safe ...
GitHub disabled 73 Microsoft repositories on June 5 after a malicious commit landed in an Azure project, in what researchers described as a supply chain attack aimed at developer workstations and AI ...
The OWASP-backed tool scans JavaScript and TypeScript lockfiles locally, aiming to help developers catch and remediate dependency risks before CI failures.
A malware named IronWorm spread through 36 npm packages in the Arweave ecosystem, stealing developer credentials and self ...
Multiple npm supply chain attacks used 50+ poisoned packages to spread IronWorm, a Rust-based stealer, and a Miasma worm ...
A large-scale campaign impersonates open-source and freeware project portals to redirect users through a gated TDS and ...
To reach protected secrets, the macOS and Linux versions show a fake password dialog, then reuse the captured password to ...
Two months after Rapid7 discovered the hole in the Git service, the project maintainer has yet to patch the bug.