Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data
A cluster of 77 malicious extensions on the Open VSX marketplace has been discovered impersonating legitimate developer tools while exfiltrating sensitive information…
A cluster of 77 malicious extensions on the Open VSX marketplace has been discovered impersonating legitimate developer tools while exfiltrating sensitive information…
A credential-stealing npm worm that first appeared in keyv@6.0.0 has spread beyond the Keyv and Cacheable namespaces into hundreds of packages across…
Cybersecurity researchers have uncovered a sophisticated software supply chain attack targeting users of Alibaba developer tools with a cross-platform remote access trojan…
Two npm packages in the @joyfill namespace, @joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4, have been compromised to deliver a remote access trojan (RAT) associated with…
A critical vulnerability in AWS Kiro, an agentic coding IDE, allowed a poisoned web page to rewrite its configuration file and execute…
Cybersecurity researchers have uncovered a sophisticated software supply chain attack dubbed 'SleeperGem' targeting the Ruby ecosystem. Three malicious gems were published to…
Cybersecurity researchers at Checkmarx have uncovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of…
Security researcher cereblab discovered that xAI's Grok Build coding CLI (version 0.2.93) was uploading entire Git repositories—including full commit history—to a Google…
Version 8.14.0 of the jscrambler npm package, published on July 11, 2026, shipped with a malicious preinstall hook that silently drops and…
Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm…