ChainDrop npm Worm Uses AI Agent Hooks
ChainDrop is an npm worm whose operators planted malicious Claude Code SessionStart hooks and VS Code folderOpen tasks in compromised repositories. The…
ChainDrop is an npm worm whose operators planted malicious Claude Code SessionStart hooks and VS Code folderOpen tasks in compromised repositories. The…
A credential-stealing npm worm that first appeared in keyv@6.0.0 has spread beyond the Keyv and Cacheable namespaces into hundreds of packages across…
Agent IDE is a Microsoft Visual Studio Code extension published in the official marketplace by a threat actor known as 'johnnysilverhe', who…
Microsoft shipped its largest Patch Tuesday on record, addressing 622 CVEs, more than triple the previous high. Two zero-days are under active…
Version 8.14.0 of the jscrambler npm package, published on July 11, 2026, shipped with a malicious preinstall hook that silently drops and…
Researchers Abhishek Kumar and Carsten Maple have discovered a novel workflow-level jailbreak method that bypasses safety guardrails in GitHub Copilot. The study,…
North Korean threat actors linked to the Contagious Interview campaign have published 108 unique malicious packages and browser extensions across npm, Packagist,…
A cluster within the PolinRider campaign that drops malicious VS Code task files into GitHub users' repositories. The tasks use 'runOn: folderOpen'…
Cybersecurity researchers have uncovered two hijacked npm packages and a cluster of Go packages designed to deploy a Python-based information stealer on…
A cluster of malicious packages that use fake .woff2 font files to conceal JavaScript payloads. Tactically overlaps with TaskJacker and PolinRider, using…