Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code HooksThe Hacker News·Aug 4, 15:03 UTC · Aug 4, 2026Malware142
Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python InfostealerThe Hacker News·Jul 1, 10:25 UTC · Jul 1, 2026Malware142
Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential StealerThe Hacker News·May 25, 09:00 UTC · May 25, 2026Malware142
Fake Moltbot AI Coding Assistant on VS Code Marketplace Drops MalwareThe Hacker News·Jan 29, 10:32 UTC · Jan 29, 2026Malware42
Malicious Pull Request Targets 6,000+ Developers via Vulnerable Ethcode VS Code ExtensionThe Hacker News·Jul 10, 10:33 UTC · Jul 10, 2025Malware142
Researchers Uncover 73 Fake VS Code Extensions Delivering GlassWorm v2 MalwareThe Hacker News·Apr 28, 04:06 UTC · Apr 28, 2026Malware42
VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain AttacksThe Hacker News·Jun 8, 17:09 UTC · Jun 8, 2026Malware42
Self-Spreading 'GlassWorm' Infects VS Code Extensions in Widespread Supply Chain AttackThe Hacker News·Oct 24, 07:00 UTC · Oct 24, 2025Malware42
Chinese TA415 Uses VS Code Remote Tunnels to Spy on U.S. Economic Policy ExpertsThe Hacker News·Sep 18, 12:42 UTC · Sep 18, 2025Malware42
Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply ChainThe Hacker News·Apr 24, 04:35 UTC · Apr 24, 2026Malware42
North Korean Hackers Are Turning Developer Tools Into Malware Delivery ChannelsThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2026Malware42
Malware Discovered in 19 Visual Studio Code ExtensionsInfosecurity Magazine·Dec 11, 16:00 UTC · Dec 11, 2025Malware42
Tropic Trooper Uses Trojanized SumatraPDF and GitHub to Deploy AdaptixC2The Hacker News·Apr 24, 09:29 UTC · Apr 24, 2026Malware42
North Korean Hackers Publish 26 npm Packages Hiding Pastebin C2 for CrossThe Hacker News·Mar 3, 06:20 UTC · Mar 3, 2026Malware42
How cybersecurity firms took down Glassworm botnet in one shotSecurity Affairs·May 27, 11:35 UTC · May 27, 2026Malware42
GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack InfrastructureThe Hacker News·May 27, 15:23 UTC · May 27, 2026Malware42
Eclipse Foundation Revokes Leaked Open VSX Tokens Following Wiz DiscoveryThe Hacker News·Nov 6, 04:40 UTC · Nov 6, 2025Malware42
Malicious npm Packages Harvest Crypto Keys, CI Secrets, and API TokensThe Hacker News·Feb 23, 10:20 UTC · Feb 23, 2026Malware142
CrowdStrike, Google Take Down Glassworm BotnetInfosecurity Magazine·May 27, 14:00 UTC · May 27, 2026Malware42
AI Coding Assistants Secretly Copying All Code to ChinaSchneier on Security·Feb 2, 12:05 UTC · Feb 2, 2026Malware42
Developer Alert: NPM Packages for Node.js Hiding Dangerous TurkoRat MalwareThe Hacker News·May 19, 12:13 UTC · May 19, 2023Malware142
GlassWorm evolves with Zig dropper to infect multiple developer toolsSecurity Affairs·Apr 11, 16:27 UTC · Apr 11, 2026Malware42
Brazilian LofyGang Resurfaces After Three Years With Minecraft LofyStealer CampaignThe Hacker News·Apr 29, 08:29 UTC · Apr 29, 2026Malware42
Eclipse Foundation Mandates Pre-Publish Security Checks for Open VSX ExtensionsThe Hacker News·Feb 4, 06:26 UTC · Feb 4, 2026Malware42
Konni Hackers Deploy AI-Generated PowerShell Backdoor Against Blockchain DevelopersThe Hacker News·Jan 26, 08:54 UTC · Jan 26, 2026Malware42
Toptal GitHub Breach Exposes 73 Repositories and Injects Malware into 10 npm PackagesThe Hacker News·Aug 6, 10:50 UTC · Aug 6, 2025Malware42
The Solidity Language open-source package was used in a $500,000 crypto heistKaspersky Securelist·Jul 10, 11:00 UTC · Jul 10, 2025Malware42
Self-spreading npm malware targets developers in new supply chain attackHelp Net Security·Feb 24, 00:00 UTC · Feb 24, 2026Malware42
Signature Validation Bug Let Malware Bypass Several Mac Security ProductsThe Hacker News·Jun 12, 15:04 UTC · Jun 12, 2018MalwareCVE-2018-10408CVE-2018-10405CVE-2018-6336+5 CVEs47
Malicious npm Package Targets Atomic Wallet, Exodus Users by Swapping Crypto AddressesThe Hacker News·Apr 10, 14:18 UTC · Apr 10, 2025Malware42
Open-source tool Sage puts a security layer between AI agents and the OSHelp Net Security·Mar 9, 00:00 UTC · Mar 9, 2026Malware42
Shai-Hulud-Like Worm Targets Developers via npm and AI ToolsInfosecurity Magazine·Feb 23, 16:00 UTC · Feb 23, 2026Malware42
DPRK Operatives Impersonate Professionals on LinkedIn to Infiltrate CompaniesThe Hacker News·Feb 11, 14:43 UTC · Feb 11, 2026Malware42
TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain AttackThe Hacker News·May 15, 00:00 UTC · May 15, 2026Malware42
Axios npm packages backdoored in supply chain attackHelp Net Security·Mar 31, 00:00 UTC · Mar 31, 2026Malware42
OpenAI hit by supply chain attack linked to malicious TanStack packagesSecurity Affairs·May 16, 09:31 UTC · May 16, 2026Malware42
Supply-chain attack using invisible code hits GitHub and other repositoriesArs Technica · Security·Mar 15, 00:00 UTC · Mar 15, 2026Malware42
GlassWorm Supply-Chain Attack Abuses 72 Open VSX Extensions to Target DevelopersThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2026Malware42
Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer AccountThe Hacker News·May 21, 05:56 UTC · May 21, 2026Malware42