MemTensor Package Compromise Exposes Developers To Cross Platform Credential Stealer
Security researchers identify compromised MemTensor npm and PyPI packages delivering sckit malware designed to steal developer credentials and sensitive cloud data.
Security researchers identify compromised MemTensor npm and PyPI packages delivering sckit malware designed to steal developer credentials and sensitive cloud data.
CrowdSec reports that a TanStack npm supply chain attack resulted in the copying of private GitHub repositories and exposed limited user and investor information.
Security researchers have uncovered malicious npm packages posing as PostCSS tools that deploy a Windows remote access trojan, highlighting ongoing software supply chain threats targeting developers and open source ecosystems.
A large scale malware campaign has compromised 10,000 GitHub repositories, using cloned projects and Trojanized ZIP files to distribute malicious payloads while evading traditional detection mechanisms.
Cybersecurity researchers uncover North Korea linked campaigns abusing GitHub repositories and Visual Studio Code projects to distribute malware targeting developers across multiple industries.
Cybersecurity researchers have uncovered IronWorm and a new Miasma worm variant targeting npm packages, stealing developer credentials and spreading malware through software supply chain attacks.
Vibe coding is accelerating AI assisted software development while significantly increasing credential exposure risks, with millions of secrets leaking through code repositories and AI workflows.