Chainguard Libraries for JavaScript provides developers with malware-free dependenciesHelp Net Security·Sep 25, 00:00 UTC · Sep 25, 2025Malware42
AI-Powered Villager Pen Testing Tool Hits 11,000 PyPI Downloads Amid Abuse ConcernsThe Hacker News·Sep 15, 00:00 UTC · Sep 15, 2025Vulnerability in the wild157
Malicious PyPI and npm Packages Discovered Exploiting Dependencies in Supply Chain AttacksThe Hacker News·Aug 19, 04:18 UTC · Aug 19, 2025Exploit / PoC157
Turning Criminal Forum Exploit Chatter Into Vulnerability Risk AnalysisRecorded Future·Jun 27, 00:00 UTC · Jun 27, 2025VulnerabilityCVE-2016-3081CVE-2015-2419CVE-2015-4852+1 CVEs47
Shell No! Adversary Web Shell Trends and Mitigations (Part 1)Recorded Future·Jun 27, 00:00 UTC · Jun 27, 2025Vulnerability42
PyPI, npm, and AI Tools Exploited in Malware Surge Targeting DevOps and Cloud EnvironmentsThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2025Malware142
New Supply Chain Malware Operation Hits npm and PyPI Ecosystems, Targeting Millions GloballyThe Hacker News·Jun 9, 16:37 UTC · Jun 9, 2025Malware42
Mimo Hackers Exploit CVE-2025-32432 in Craft CMS to Deploy Cryptominer and ProxywareThe Hacker News·Jun 2, 10:07 UTC · Jun 2, 2025VulnerabilityCVE-2025-32432CVE-2021-44228CVE-2022-26134+1 CVEs47
Malicious Machine Learning Model Attack Discovered on PyPIInfosecurity Magazine·May 27, 14:00 UTC · May 27, 2025Malware42
Malicious PyPI Packages Exploit Instagram and TikTok APIs to Validate User AccountsThe Hacker News·May 20, 05:49 UTC · May 20, 2025Malware142
Researchers Uncover Malware in Fake Discord PyPI Package Downloaded 11,500+ TimesThe Hacker News·May 7, 07:37 UTC · May 7, 2025Malware42
U.S. CISA adds Langflow flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 6, 13:00 UTC · May 6, 2025Exploit / PoC in the wildCVE-2025-324860
Malicious PyPI Package "automslc" Enables 104K+ Unauthorized Deezer Music DownloadsThe Hacker News·Feb 27, 07:04 UTC · Feb 27, 2025Malware42
Fake GitHub projects distribute stealers in GitVenom campaignKaspersky Securelist·Feb 25, 06:21 UTC · Feb 25, 2025Malware42
Lazarus Group Targets Bitdefender Researcher with LinkedIn Job ScamInfosecurity Magazine·Feb 6, 14:50 UTC · Feb 6, 2025Threat actor57
Talos IR trends Q4 2024: Web shell usage and exploitation of publicCisco Talos·Jan 30, 11:00 UTC · Jan 30, 2025Ransomware57
Russian Cyber Spies Target Organizations with Custom MalwareInfosecurity Magazine·Nov 22, 13:00 UTC · Nov 22, 2024MalwareCVE-2024-2369247
China-Linked CeranaKeeper Targeting Southeast Asia with Data ExfiltrationThe Hacker News·Oct 2, 15:21 UTC · Oct 2, 2024Malware42
Researchers Identify Over 20 Supply Chain Vulnerabilities in MLOps PlatformsThe Hacker News·Aug 28, 03:53 UTC · Aug 28, 2024VulnerabilityCVE-2024-27132CVE-2023-48022CVE-2023-46229+1 CVEs47
Rogue PyPI Library Solana Users, Steals Blockchain Wallet KeysThe Hacker News·Aug 11, 10:01 UTC · Aug 11, 2024Malware42
North Korea-Linked Malware Targets Developers on Windows, Linux, and macOSThe Hacker News·Aug 1, 09:30 UTC · Aug 1, 2024Malware42
Understanding NullBulge, the New AIInfosecurity Magazine·Jul 17, 15:00 UTC · Jul 17, 2024Ransomware57
Popular PyPI site for developers temporarily blocks functions due to malware campaignThe Record·Mar 28, 19:11 UTC · Mar 28, 2024Malware42
New macOS Malware Targets Cracked AppsInfosecurity Magazine·Jan 22, 16:30 UTC · Jan 22, 2024Malware42
New MrAnon Stealer Malware Targeting German Users via BookingThe Hacker News·Dec 12, 09:57 UTC · Dec 12, 2023Malware42
YoroTrooper: Researchers Warn of Kazakhstan's Stealthy Cyber Espionage GroupThe Hacker News·Oct 26, 13:39 UTC · Oct 26, 2023Threat actor57
Japanese Cryptocurrency Exchange Falls Victim to JokerSpy macOS Backdoor AttackThe Hacker News·Jun 28, 05:25 UTC · Jun 28, 2023Malware42
PyPI enforces 2FA to prevent maintainers' account takeoverSecurity Affairs·May 30, 17:37 UTC · May 30, 2023Malware42
PyPI Repository Under Attack: User Sign-Ups and Package Uploads Temporarily HaltedThe Hacker News·May 23, 06:19 UTC · May 23, 2023Malware42
Developer Alert: NPM Packages for Node.js Hiding Dangerous TurkoRat MalwareThe Hacker News·May 19, 12:13 UTC · May 19, 2023Malware142
Attackers Flood NPM Repository with Over 15,000 Spam Packages Containing Phishing LinksThe Hacker News·Feb 22, 11:17 UTC · Feb 22, 2023Phishing & fraud42
PyTorch Machine Learning Framework Compromised with Malicious DependencyThe Hacker News·Jan 5, 05:00 UTC · Jan 5, 2023Data breach157
Researchers Uncover PyPI Package Hiding Malicious Code Behind Image FileThe Hacker News·Nov 10, 12:44 UTC · Nov 10, 2022Threat actor57
Developer account body snatchers pose risks to the software supply chainCisco Talos·Oct 4, 12:51 UTC · Oct 4, 2022Exploit / PoC57
EvilProxy phishing-as-a-service with MFA bypass emerged on the dark webHelp Net Security·Sep 6, 00:00 UTC · Sep 6, 2022Phishing & fraud42