Cybersecurity researchers have uncovered a sophisticated software supply chain attack dubbed 'SleeperGem' targeting the Ruby ecosystem. Three malicious gems were published to…
Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security,…
Socket was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
GitHub has officially released npm version 12, introducing significant security changes to reduce software supply chain risks. The most notable change is…
North Korean threat actors linked to the Contagious Interview campaign have published 108 unique malicious packages and browser extensions across npm, Packagist,…
Cybersecurity researchers have flagged an active browser extension campaign designed to steal cryptocurrency by stealthily replacing wallet addresses during transactions. The cryptocurrency…