Red Hat hit by npm supply‑chain attack - here's how to stay safe ...
The Miasma credential-stealing attack framework, which has recently targeted open-source ecosystems through supply-chain ...
The popular Mastra AI framework, used to build artificial intelligence agents, workflows and retrieval-augmented generation ...
The Miasma supply chain campaign has sparked a fresh attack wave called Hades, this time involving 37 malicious wheel ...
Microsoft Threat Intelligence identified a large-scale npm supply chain attack affecting 32 maliciously modified packages across more than 90 versions under the ...
Mastra npm packages added easy-day-js malware, exposing developer systems and CI runners to infostealer risks.
Hackers compromised 19 packages on the PyPI, collectively downloaded hundreds of thousands of times, in a new Shai-Hulud ...
Researchers have uncovered a supply-chain attack that hides in Python packages, propagates like a worm, and tricks LLM-based ...
With the rise of AI coding assistants continuing apparently unabated, some project maintainers have begun striking back. Ars Technica reports on projects putting hostile directions into the ...
A long-running phishing operation has been stealing banking credentials from customers of Mexican financial institutions ...