Aikido traced Go malware inside two Terraform providers and two Go modules, the first abuse of HashiCorp's registry as a…
A malicious npm package pulled two million weekly downloads while running its payload from ordinary library code instead of an…
A small JavaScript stealer with fingerprints of North Korean developer-targeting campaigns has been found riding a cluster of malicious packages.
Trend Micro finds 14 trojanized packages that drop the RedC2 4.0 implant the moment they are imported.
Nearly 800 npm packages hide a cross-platform RAT and infostealer behind fake README instructions.
A campaign of nearly 800 npm packages uses README lures and DNS tricks to deliver RATs on every platform.
The Mini Shai-Hulud worm stole publisher credentials, republished tainted packages, and burrowed into AI coding tools.
Amazon attributes the debug and chalk npm hijacks to the North Korean group behind the axios attack.