MemTensor Package Compromise Exposes Developers To Cross Platform Credential Stealer
Security researchers identify compromised MemTensor npm and PyPI packages delivering sckit malware designed to steal developer credentials and sensitive cloud data.
Security researchers identify compromised MemTensor npm and PyPI packages delivering sckit malware designed to steal developer credentials and sensitive cloud data.
Researchers have uncovered the SleeperGem software supply chain attack involving malicious RubyGems packages designed to compromise developer machines and establish persistent access.
A newly disclosed Cursor vulnerability allows malicious Git repositories on Windows to execute arbitrary code by placing a fake git.exe file in the project root, with no security patch currently available.
Security researchers have uncovered malicious npm packages posing as PostCSS tools that deploy a Windows remote access trojan, highlighting ongoing software supply chain threats targeting developers and open source ecosystems.
Researchers have uncovered a supply chain attack targeting the Mastra npm ecosystem, where more than 140 packages were compromised through a hijacked contributor account and a malicious dependency designed to steal cryptocurrency wallet data and sensitive credentials.
Cybersecurity researchers have uncovered a coordinated campaign involving malicious JetBrains Marketplace plugins and Chrome extensions designed to steal AI provider API keys and capture private conversations from popular AI chat platforms.
Cybersecurity researchers uncover North Korea linked campaigns abusing GitHub repositories and Visual Studio Code projects to distribute malware targeting developers across multiple industries.
Cybersecurity researchers have uncovered a new attack method called Agentjacking that tricks AI coding agents into executing malicious code through fake Sentry error reports, exposing developers and organizations to serious security risks.
Cybersecurity researchers have uncovered IronWorm and a new Miasma worm variant targeting npm packages, stealing developer credentials and spreading malware through software supply chain attacks.
Cybersecurity researchers have disclosed a one click attack affecting GitHub.dev through VS Code that could allow attackers to steal GitHub OAuth tokens with access to private repositories.