Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks
A credential-stealing npm worm that first appeared in keyv@6.0.0 has spread beyond the Keyv and Cacheable namespaces into hundreds of packages across…
A credential-stealing npm worm that first appeared in keyv@6.0.0 has spread beyond the Keyv and Cacheable namespaces into hundreds of packages across…
GitHub has announced a new cooldown mechanism for Dependabot that introduces a mandatory three-day waiting period before opening pull requests for version…
Bun is a JavaScript runtime that the worm's stage one downloads (version 1.3.13) to execute a compiled credential-stealing bundle.
The Bun runtime, a legitimate JavaScript runtime built on Apple's JavaScriptCore engine, is used by the SourTrade malvertising campaign as a base…
Cybersecurity researchers have flagged a new evolution of the supply chain attack linked to the Mini Shai-Hulud, Miasma, and Hades malware family,…
The npm package js-digest was used in a second wave of the Atomic Arch attack, delivered via bun install. It contained a…