Keyv: npm Package and Worm Vector
Keyv is an npm package that was compromised in the August 2026 worm campaign. The malicious keyv@6.0.0 release included a preinstall script…
Keyv is an npm package that was compromised in the August 2026 worm campaign. The malicious keyv@6.0.0 release included a preinstall script…
A sophisticated cross-platform remote access trojan (RAT) was delivered via malicious npm packages impersonating Alibaba's private packages. The RAT is capable of…
Alibaba Group's developer tools were targeted in a software supply chain attack via malicious npm packages impersonating private @ali-scoped packages. The attack…
Xanadu's photonic quantum computing Python library, mrmustard, was compromised with a poisoned version that ran an information stealer. The attack involved breaching…
A poisoned version of the mrmustard Python library from Xanadu was published to run an information stealer that harvests SSH keys, AWS…
Adform is an advertising technology company that detected and responded to a supply-chain compromise of its JavaScript file trackpoint-async.js, which was used…
Cybersecurity firm Bitsight has uncovered a large-scale operation dubbed 'Fuyao' involving cheap Android TV boxes that secretly impersonate smartphones to commit ad…
Cheap Android TV boxes, particularly models like H96_MAX_V11, are the primary devices affected by the Fuyao operation. They are shipped with malicious…
INL was cited in the FCC determination for its research on supply-chain and remote-connectivity risks related to power inverters.
Hugging Face is a leading platform for AI models, often called the 'GitHub of the AI era'. Its Diffusers library is widely…