NPM flooded with 748 packages that store movies

PyPI Package 'Secretslib' Drops Fileless Linux Malware to Mine Monero

PyPI: Python packets steal AWS keys from users

0-Day Vulnerability on Log4j

Fake npm Roblox API Package Installs Ransomware and has a Spooky Surprise

Ua-parser-js highjack seems to be a part of a larger campaign first uncovered last week

New PyPI crypto mining malware identified

Why Namespacing Matters in Public Open Source Repositories

Dear Bintray and JCenter Users - Here’s What You Need to Know About The Central Repository

Dependency Hijacking Software Supply Chain Attack Hits More Than 35 Organizations

ZeroTrustOps: Securing at Scale

jackson-databind 2.10, The End of the Blacklist