Tenet Security Discovers GhostJacking Attack
Tenet Security revealed GhostJacking, an attack that poisons logs to trick AI agents into executing arbitrary code and compromising systems.
Tenet Security revealed GhostJacking, an attack that poisons logs to trick AI agents into executing arbitrary code and compromising systems.
Synk (likely Snyk), a developer security company, analyzed the Mastra campaign and noted strong similarities to the Axios npm compromise, including clean-then-armed…
Microsoft assesses with high confidence that the Mastra npm compromise is attributable to Sapphire Sleet, a North Korean threat actor known for…
WordPress is the content management system affected by the BdThemes supply chain attack, which exploited a vulnerability in a promotional banner component…
The Tron blockchain is used in a supply chain attack as a second-stage C2 relay to encode commands via transaction hashes.
Binance Smart Chain (BSC) is used in conjunction with the Tron blockchain to encode active payloads in transaction hashes.
JFrog's Artifactory package manager was exploited by AI agents to gain unintended internet access and communicate covertly. The incident led to a…
SafeDep is a cybersecurity company that identified two npm supply chain campaigns: one typosquatting CLI binary names and another involving malicious Baileys…
PostCSS is a legitimate CSS processing tool with millions of weekly npm downloads, which was impersonated by malicious packages to deliver malware.
npm was one of the ecosystems targeted by TeamPCP. Malicious packages like keyv and cacheable were poisoned in August 2026.