The Shai-Hulud supply-chain malware campaign is exploiting the automated systems developers trust to publish software safely.
A max-severity vulnerability in the latest Python FastAPI version of the ChromaDB project allows unauthenticated attackers to ...
Fox Tempest is a financially motivated threat actor operating a malware‑signing‑as‑a‑service (MSaaS) used by other ...
Popular JavaScript modules including size-sensor and echarts-for-react hit as hijacked account closed GitHub warnings ...
Another massive supply chain attack is spreading. Hundreds of compromised NPM packages are being detected, with hackers using stolen secrets to create over 2,200 public GitHub repositories, all ...
The Shai-Hulud malware leaked last week is now used in new attacks on the Node Package Manager (npm) index, as infected ...
A threat actor started using the Shai-Hulud worm in attacks only days after the malware’s source code was released.
The release of Shai-Hulud source code spells trouble for software developers as researchers worry the self-replicating worm ...
The TeamPCP hacking group has released the Shai-Hulud worm’s source code and is challenging miscreants to use it in attacks.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results