BleepingComputer·16h ago highGitHub Actions re-enabled with Mini Shai-Hulud payload still active#github-actions#supply-chain#mini-shai-hulud 2 sources in the wild 2 min
Malwarebytes Labs·1d agoKothamine malware uses Tailscale’s tailcat to evade network detection#kothamine#rat#npm in the wild 11 min1
BleepingComputer·2d ago highMalicious npm packages evade install-script defenses at runtime#checkmarx#ethereum#javascript 8 sources in the wild 3 min
Datadog Security Labs·3d ago highDiscovering and exploiting a remote code execution vulnerability in OpenCode (GHSA-632h-h47v-g4x4)#opencode#rce#content-type-confusion 11 min
The Hacker News·3d ago highCompromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI#credential-stealer#exfiltration#github-actions 4 sources in the wild 3 min1
oss-security·3d agonpm registry keeps removed-version timestamps but drops the reason (Sept 2025 campaign as evidence)#npm#supply-chain#package-registryResearch
Dark Reading·4d ago highShai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub Data#shai-hulud#crowdsec#github 3 sources in the wild
Infosecurity Magazine·4d ago highNorth Korean Attackers Hit 30,000 Devices and Steal $10.7m#north-korea#waterplum#contagious-interview 5 sources in the wild 2 min2
Infosecurity Magazine·4d ago highAttackers Abuse npm Trusted Publishing in GHAPPIER Campaign#ghappier#github-actions#loader 3 sources in the wild 2 min
arXiv cs.CR·6d agoKEVGraph: Exploitation-Aware Dependency Vulnerability Remediation#kev#dependency-scanning#supply-chainResearch
BleepingComputer·7d ago highNorth Korean WaterPlum hackers infected 30,000 devices worldwide#beavertail#contagious-interview#cryptocurrency-theft in the wild 3 min
Cyber Security News·7d ago highTanStack Supply Chain Attack Lets Hackers Steal 170 Private CrowdSec GitHub Repositories#credential-harvesting#crowdsec#github in the wild 4 min
The Hacker News·7d ago highCrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories#credential-theft#crowdsec#data-leak in the wild 4 min
The Hacker News·8d agoWeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage#beavertail#contagious-interview#dprk in the wild 3 min1
The Hacker News·8d agoClaimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer#infostealer#llm#npm in the wild 3 min1
arXiv cs.CR·10d agoCASHEWS: Source Preprocessor for LLM-based Malicious Package Detection#code-obfuscation#llm#malicious-package-detectionResearch
Infosecurity Magazine·18d ago highAI Coding Tools Now a Prime Target for Threat Actors, Google Warns#credential-stealer#dustmaker#espionage 2 sources in the wild 4 min1
The Hacker News·23d agoShai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means#ci-cd#credential-harvesting#infostealer in the wild 11 min1
Help Net Security·24d agoYour threat feed is someone else's database: What ingesting malware intel at scale takes#dependabot#github#malware 5 min1
The Hacker News·25d agoOpen VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data#data-exfiltration#extensions#malware 6 min1
The Hacker News·29d ago high⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More#cl0p#gitlab#npm in the wild 13 min1
Security Affairs·Aug 27, 2026 highTwo Arrests, One Supply-Chain Attack, and a Lot of Stolen Credentials#aws#exfiltration#kubernetes in the wild 5 min1
The Hacker News·Aug 27, 2026 highAlleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks#australia#checkmarx-kics#litellm in the wild 4 min1