Developer account body snatchers pose risks to the software supply chainCisco Talos·Oct 4, 12:51 UTC · Oct 4, 2022Exploit / PoC57
Malicious PyPI and npm Packages Discovered Exploiting Dependencies in Supply Chain AttacksThe Hacker News·Aug 19, 04:18 UTC · Aug 19, 2025Exploit / PoC157
Researchers Uncover Obfuscated Malicious Code in PyPI Python PackagesThe Hacker News·Feb 11, 10:33 UTC · Feb 11, 2023Exploit / PoC157
AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code ExecutionThe Hacker News·Jun 19, 15:30 UTC · Jun 19, 2026Exploit / PoCCVE-2026-26030CVE-2026-25592160
Compromised AsyncAPI npm Packages Deliver MultiThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Exploit / PoC157
How security teams are getting credential visibility into developer endpointsHelp Net Security·Jun 18, 00:00 UTC · Jun 18, 2026Exploit / PoC57
⚡ Weekly Recap: Instagram Account Hacks, Android ZeroThe Hacker News·Jun 9, 05:53 UTC · Jun 9, 2026Exploit / PoC in the wildCVE-2025-48595CVE-2026-28318CVE-2026-39210+43 CVEs60