Anthropic says its AI hacked realThe Record·Jul 31, 12:16 UTC · Jul 31, 2026Data breach in the wild60
Anthropic's Claude breached three companies during security testsHelp Net Security·Jul 31, 00:00 UTC · Jul 31, 2026Data breach45
The serpent’s tongue: Luring the Python out of its denCisco Talos·Jul 14, 10:00 UTC · Jul 14, 2026Malware155
N. Korean Hackers Spread 1,700 Malicious Packages Across npm, PyPI, Go, RustThe Hacker News·Apr 8, 07:47 UTC · Apr 8, 2026Malware142
Malicious LiteLLM versions linked to TeamPCP supply chain attackSecurity Affairs·Mar 25, 08:50 UTC · Mar 25, 2026Data breach57
npm, PyPI, and RubyGems Packages Found Sending Developer Data to Discord ChannelsThe Hacker News·Oct 15, 00:00 UTC · Oct 15, 2025Data breach157
Alert: Malicious PyPI Package soopsocks Infects 2,653 Systems Before TakedownThe Hacker News·Oct 2, 13:07 UTC · Oct 2, 2025Malware42
Chinese AI Villager Pen Testing Tool Hits 11,000 PyPI DownloadsInfosecurity Magazine·Sep 16, 16:00 UTC · Sep 16, 2025Malware in the wild57
This Malicious PyPI Package Stole Ethereum Private Keys via Polygon RPC TransactionsThe Hacker News·Mar 7, 09:51 UTC · Mar 7, 2025Data breach57
Researchers Uncover PyPI Packages Stealing Keystrokes and Hijacking Social AccountsThe Hacker News·Dec 24, 13:22 UTC · Dec 24, 2024Malware30
Malicious PyPI Package Targets macOS to Steal Google Cloud CredentialsThe Hacker News·Jul 27, 05:47 UTC · Jul 27, 2024Malware42
GitHub Token Leak Exposes Python's Core Repositories to Potential AttacksThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2024Exploit / PoC in the wild160
Hackers Hijack GitHub Accounts in Supply Chain Attack Affecting TopThe Hacker News·Mar 26, 03:55 UTC · Mar 26, 2024Malware142
Lazarus Exploits Typos to Sneak PyPI Malware into Dev SystemsThe Hacker News·Feb 29, 10:58 UTC · Feb 29, 2024Malware30
Beware: 3 Malicious PyPI Packages Found Targeting Linux with Crypto MinersThe Hacker News·Jan 6, 06:24 UTC · Jan 6, 2024Malware30
Beware, Developers: BlazeStealer Malware Discovered in Python Packages on PyPIThe Hacker News·Nov 9, 04:36 UTC · Nov 9, 2023Malware42
Malicious PyPI packages drop ransomware, fileless malwareHelp Net Security·Jun 5, 12:37 UTC · Jun 5, 2023Ransomware57
Malicious PyPI Packages Using Compiled Python Code to Bypass DetectionThe Hacker News·Jun 3, 05:06 UTC · Jun 3, 2023Malware142
Malicious PyPI Packages Using Cloudflare Tunnels to Sneak Through FirewallsThe Hacker News·Jan 9, 08:47 UTC · Jan 9, 2023Malware42
Week in review: Windows EoP flaw still exploitable, GoDaddy breach, malicious Python packages on PyPIHelp Net Security·Nov 28, 00:00 UTC · Nov 28, 2021RansomwareCVE-2021-41379160
AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code ExecutionThe Hacker News·Jun 19, 15:30 UTC · Jun 19, 2026Exploit / PoCCVE-2026-26030CVE-2026-25592160
Open-source security group pulls out of U.S. grant, citing DEI restrictionsCyberScoop·Oct 29, 20:55 UTC · Oct 29, 2025Exploit / PoC in the wild160
Malicious Python Package uses Unicode to evade detectionSecurity Affairs·Mar 27, 07:05 UTC · Mar 27, 2023Malware142
Hundreds of Malicious Packages Found in npm RegistryInfosecurity Magazine·Jan 19, 09:30 UTC · Jan 19, 2023Malware42
PyTorch compromised to demonstrate dependency confusion attack on Python environmentsSecurity Affairs·Jan 2, 18:57 UTC · Jan 2, 2023Vulnerability142
Two malicious Python libraries were stealing SSH and GPG keysSecurity Affairs·Dec 4, 15:37 UTC · Dec 4, 2019Malware30
TeamPCP Targets Telnyx Package in Latest Software Supply Chain AttackInfosecurity Magazine·Mar 27, 15:06 UTC · Mar 27, 2026Ransomware57
An AI gateway designed to steal your dataKaspersky Securelist·Mar 27, 13:36 UTC · Mar 27, 2026Malware42
Anthropic backs Python Software Foundation security work with $1.5 millionHelp Net Security·Jan 14, 00:00 UTC · Jan 14, 2026Malware142
Legacy Python Bootstrap Scripts Create DomainThe Hacker News·Dec 1, 04:21 UTC · Dec 1, 2025VulnerabilityCVE-2023-45311147
Malicious MCP servers used in supply chain attacksKaspersky Securelist·Sep 15, 10:00 UTC · Sep 15, 2025AI safety & security30
GhostAction Supply Chain Attack Compromises 3000+ SecretsInfosecurity Magazine·Sep 8, 11:00 UTC · Sep 8, 2025Threat actor57
Researchers Find VS Code Flaw Allowing Attackers to Republish Deleted Extensions Under Same NamesThe Hacker News·Aug 29, 03:58 UTC · Aug 29, 2025Ransomware157
Hackers Distributing Malicious Python Packages via Popular Developer Q&A PlatformThe Hacker News·Aug 3, 03:47 UTC · Aug 3, 2024Vulnerability142
Developers can’t seem to stop exposing credentials in publicly accessible codeArs Technica · Security·Nov 15, 00:00 UTC · Nov 15, 2023AI tools & infra130
Malicious npm packages caught stealing Discord tokens, environment variablesThe Record·Dec 21, 00:00 UTC · Dec 21, 2022Vulnerability30