A small JavaScript stealer with fingerprints of North Korean developer-targeting campaigns has been found riding a cluster of malicious packages.
The Mini Shai-Hulud worm stole publisher credentials, republished tainted packages, and burrowed into AI coding tools.
Five AsyncAPI npm packages with 2.9 million weekly downloads were trojanized after a GitHub Actions token theft.
Tenet Security researchers discovered a technique called Agentjacking that uses crafted Sentry error reports to trick AI coding assistants into…
The threat actors infiltrated legitimate npm packages for SAP, Lightning, and Intercom to deploy credential-harvesting code, compromising over 1,800 developers.