The NPM ecosystem has suffered another supply chain attack in which a malicious package has accumulated millions of downloads ...
A malicious npm package reached over 2 million weekly downloads by hiding its payload in a routine library function rather than an install script.
Malicious Terraform providers and Go modules deliver Graphalgo-linked Go malware using blockchain and Slack for command and ...
Die mutmaßlich chinesische Gruppe griff Regierungsstellen mit einer Chrome-Windows-Exploit-Kette und der Malware CLEANGULP an ...
The "third-party.com" domain, commonly used as a placeholder in developer documentation and code examples, is serving a fake ...
Malicious npm package indexed-btree hid its loader in runtime code, avoiding install hooks after logging millions of downloads.
The Swift Package Manager (SwiftPM), created by Apple in 2015, is a command line automation and dependency management tool.
Researchers find attackers now infect widely used package at runtime, sidestepping recent lifecycle-script restrictions entirely. chaeckmarx ## A New Evasion Technique Emerges ...
WordPress Click2Shell vulnerability lets attackers silently install themes on any admin’s site via a single crafted link, ...
GitHub's npm registry shipped staged publishing in May 2026, the first mandatory 2FA human checkpoint in its 16-year history, ...
CrowdStrike links PhantomRaven malware to a bug bounty hunter, finding LLM-generated code, malicious npm packages and ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results