Browsing: Packages
Cybersecurity firm Socket has issued a warning about a new malware campaign dubbed ‘TrapDoor’ that specifically targets software developers working…
Key TakeawaysMini Shai-Hulud exploited GitHub Actions on May 19, compromising 300+ npm packages across 16M weekly downloads.The malware installs a…
Four npm packages that were connected to SAP’s Cloud Application Programming Model were stolen. The hackers added code that steals…
Ethereum and Solana developers were targeted by five malicious npm packages that steal private keys and send them to the…
A new supply-chain threat is putting developers on alert. Security researchers warn that North Korean hackers have uploaded 26 malicious…
A recent investigation by security researchers has revealed a troubling surge in malicious campaigns exploiting popular development tools, including VSCode…
A series of high-profile compromises targeting popular open source packages have been uncovered, exposing the growing risk of malicious code…
Researchers have uncovered a highly sophisticated North Korean campaign to covertly distribute crypto-stealing malware via open source components. SecurityScorecard said…
Researchers have uncovered a highly sophisticated North Korean campaign to covertly distribute crypto-stealing malware via open source components. SecurityScorecard said…
A malicious campaign targeting developers through npm and GitHub repositories has been uncovered, featuring an unusual method of using Ethereum…
