Someone compromised SAP's npm packages and used the CI pipeline against itself

@fairwords npm packages compromised by a self-propagating credential worm - steals tokens, infects other packages you own, then crosses to PyPI

Someone is actively publishing malicious packages targeting the Strapi plugin ecosystem right now

Dependency cooldown using the publish age as a signal for package resolution

axios 1.14.1 and 0.30.4 on npm are compromised - dependency injection via stolen maintainer account

TeamPCP strikes again - telnyx 4.87.1 and 4.87.2 on PyPI are malicious

Malicious litellm 1.82.8: Credential Theft and Persistent Backdoor

Using CEL's now() to enforce dependency cooldown periods - block packages published in the last N hours

Agent Skills Threat Model

Reverse Engineering Malicious Visual Studio Code Extension DarkGPT

React RCE vul technical blog

Shai-Hulud Second Coming: Software Supply Chain Attack Exposing Code and Harvesting Credentials

Curious Case of Embedded Executable in a Newly Introduced Go Transitive Dependency

Self-replicating worm like behaviour in latest npm Supply Chain Attack

TensorFlow.js Typosquatting Attack: Malicious Package Targeting AI/ML Developers

eslint-config-prettier Compromised: How npm Package with 30 Million Downloads Spread Malware

Malicious npm eslint-config-airbnb-compat Package Hides Detection with Payload Splitting

Malicious npm Package Impersonating Popular Express Cookie Parser