Threat actors earlier today published more than 600 malicious packages to the Node Package Manager (npm) index as part of a ...
Mini Shai-Hulud npm campaign compromises @antv packages, targeting blockchain developers' GitHub tokens, AWS keys, and CI/CD ...
The updated SHub stealer variant is called Reaper, and it uses macOS Script Editor, pre-populated with the malicious payload ...
Four supply-chain attacks hit OpenAI, Anthropic, and Meta in 50 days — none inside the model. A 7-row matrix maps what AI ...
We tested both on writing, coding, research, and video. See which one fits your workflow, budget, and use case.
Sometime around the last week of May 2026, attackers uploaded poisoned packages to three of the most widely used software ...
If you use Drupal, get ready to patch without delay. The org behind the popular open source content management system is ...
The world’s largest open-source registry, node package manager (npm), has been hit by another fast-moving malware attack, ...
Anthropic acquired Stainless, the SDK compiler behind OpenAI, Gemini and Llama. The deal hands one AI lab structural leverage ...
What is Mini Shai-Hulud npm supply chain attack, and was Microsoft and Socket hit by malware? A new npm supply chain attack ...
Another massive supply chain attack is spreading. Hundreds of compromised NPM packages are being detected, with hackers using stolen secrets to create over 2,200 public GitHub repositories, all ...