SleeperGem: RubyGems Supply Chain Attack
SleeperGem is a software supply chain attack targeting the Ruby ecosystem through three malicious RubyGems packages. The malware acts as a loader,…
SleeperGem is a software supply chain attack targeting the Ruby ecosystem through three malicious RubyGems packages. The malware acts as a loader,…
North Korean threat actors linked to the Contagious Interview campaign have been observed using steganography in SVG image files to conceal malicious…
A malware framework called OkoBot has been targeting Windows machines since April 2025, with a module named SeedHunter designed to steal cryptocurrency…
Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security,…
A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service (DDoS) botnet for roughly…
A self-replicating worm that hit more than 500 npm packages in September 2025, harvesting developer secrets and republishing itself with stolen tokens.
Version 8.14.0 of the jscrambler npm package, published on July 11, 2026, shipped with a malicious preinstall hook that silently drops and…
A Rust-based infostealer was distributed through a compromised version of the jscrambler npm package. It steals cloud credentials, cryptocurrency wallets, password manager…
tj-actions/changed-files is a GitHub Action used to detect file changes in pull requests. It was compromised in a 2025 tag hijack attack,…
trivy-action is a GitHub Action for running Trivy vulnerability scans. It was compromised in a 2026 tag hijack attack, which this research…