Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly ...
BSides Las Vegas 2026 spent three days making the case that AI coding tools are supply chain attack targets. ChainDrop, a ...
More than 400 NPM packages have been infected with the Mini Shai-Hulud worm in the ChainDrop supply chain attack.
Security researchers have warned of a major new Shai-Hulud-based campaign which has already compromised more than 430 ...
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems ...
The Shai Hulud variant’s blast radius includes several highly popular packages thus far.. Security teams are urged to perform ...
Another Shai-Hulud variant hits npm packages, worming its way into hundreds of packages.
Open VSX removes 77 evil twin extensions that impersonate developer tools and exfiltrate host, workspace, Git, and CI data.
A self-spreading worm poisoned hundreds of npm packages in hours, slipped past provenance checks, hid its controls on Ethereum, and hunted AI-tool keys.
A self-propagating malware campaign has compromised more than 430 npm packages, exposing software projects linked to dependencies that collectively record about two billion installations each month.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results