Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware
Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security,…
Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security,…
Version 8.14.0 of the jscrambler npm package, published on July 11, 2026, shipped with a malicious preinstall hook that silently drops and…
Researchers at Noma Security have demonstrated a novel prompt injection attack, dubbed GitLost, that exploits GitHub Agentic Workflows to leak private repository…
GitHub has announced a critical security update to its official actions/checkout action, effective June 18, 2026, designed to block common pwn request…
GitHub had previously documented the risk of expanding untrusted issue data in workflow run blocks. The Snowflake incident underscores the importance of…
Cybersecurity researchers at Novee Security have identified a critical exploitable pattern in CI/CD workflows, codenamed Cordyceps, that allows unauthenticated attackers to hijack…