Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks
A credential-stealing npm worm that first appeared in keyv@6.0.0 has spread beyond the Keyv and Cacheable namespaces into hundreds of packages across…
A credential-stealing npm worm that first appeared in keyv@6.0.0 has spread beyond the Keyv and Cacheable namespaces into hundreds of packages across…
Cybersecurity researchers have uncovered a sophisticated software supply chain attack targeting users of Alibaba developer tools with a cross-platform remote access trojan…
Cybersecurity researchers have disclosed a maximum-severity vulnerability in Ruflo, an open-source AI multi-agent orchestration platform, that could allow unauthenticated attackers to achieve…
Two npm packages in the @joyfill namespace, @joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4, have been compromised to deliver a remote access trojan (RAT) associated with…
Security researcher Yuhang Wu at depthfirst has published a working proof-of-concept (PoC) exploit for a remote code execution (RCE) vulnerability in self-managed…
Cybersecurity researchers at Checkmarx have uncovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of…
Version 8.14.0 of the jscrambler npm package, published on July 11, 2026, shipped with a malicious preinstall hook that silently drops and…
Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm…
The cybersecurity landscape is witnessing a surge in vulnerability clearinghouse announcements, but according to this analysis, most will fail because they focus…