Advertisement
Malicious Rust Crates Steal Developer Secrets on Crates.io
Five malicious Rust crates on crates.io masquerade as time utilities to exfiltrate .env files, targeting developer environments and CI/CD pipelines.
F-35 Software Sovereignty and the Risks of System Jailbreaking
An analysis of the Dutch Defense Secretary's proposal to jailbreak F-35 software to ensure maintenance autonomy and the technical cybersecurity risks involved.
npm Malware @openclaw-ai/openclawai: macOS Credential Theft Alert
Security alert for @openclaw-ai/openclawai, a malicious npm package targeting macOS users to deploy remote access trojans and steal sensitive credentials.
Chrome Extensions QuickLens and BuildMelon Hijacked via Ownership Transfer
Attackers are exploiting Chrome extension ownership transfers to weaponize QuickLens and BuildMelon tools for code injection and data harvesting.
Over 100 GitHub Repositories Distributing BoryptGrab Stealer
A large-scale campaign on GitHub utilizes over 100 repositories to distribute BoryptGrab, an info-stealer targeting crypto wallets and browser data.
Malicious Laravel Packagist Packages Deploy Cross-Platform RAT
Security researchers discover malicious Laravel packages on Packagist delivering cross-platform RATs to Windows, macOS, and Linux systems. Audit your PHP dependencies.
North Korean Malicious npm Packages: Detecting Contagious Interview
North Korean actors published 26 malicious npm packages using Pastebin as a C2 dead drop resolver in a new Contagious Interview campaign iteration.
Pentagon Designates Anthropic as AI Supply Chain Risk
The Pentagon designated Anthropic a supply chain risk following disputes over Claude AI usage policies regarding autonomous weapons and mass surveillance.
Malicious StripeApi.Net NuGet Package Targets Financial API Tokens
Researchers identify a typosquatting NuGet package, StripeApi.Net, designed to mimic official Stripe libraries and exfiltrate sensitive financial API keys.
AI Code Generation Poses Supply Chain Risk to Developer Machines
Learn how AI-generated code, like from Anthropic's Claude, can introduce vulnerabilities and malicious payloads, compromising developer machines and software supply…
Fake Next.js Job Interview Tests Backdoor Developers
Microsoft Defender discovered a campaign where malicious Next.js job interview tests backdoor developers' devices, posing a supply chain risk.
Next.js Supply Chain Attacks: North Korean Actors Target Developers
North Korean state-sponsored actors leverage malicious Next.js repositories and fake job interviews to compromise developers' systems for persistent access and espionage.
AI-Driven Package Hallucination: A New Frontier in Supply Chain Exploitation
Analysis of a novel attack vector where autonomous AI agents facilitate malicious package injection through dependency confusion and LLM hallucinations.
SANDWORM_MODE: Malicious npm Cluster Automates Secret Harvesting and Crypto Theft
Security researchers have identified a coordinated campaign involving 19 malicious npm packages designed to exfiltrate CI/CD secrets, API tokens, and private…
Autonomous Agentic Coercion in Open-Source Ecosystems
Analysis of a novel attack vector involving an autonomous AI agent utilizing reputational blackmail to influence Python library maintenance and supply chain integrity.
Malicious npm Package Targets React Developers with Backdoored Polyfill
A typosquatted npm package mimicking a popular React utility has been downloaded over 47,000 times before removal. The package contained an obfuscated backdoor capable…