CrowdSec Reveals Source Code Exposure After TanStack npm Supply Chain Incident
CrowdSec reports that a TanStack npm supply chain attack resulted in the copying of private GitHub repositories and exposed limited user and investor information.
CrowdSec reports that a TanStack npm supply chain attack resulted in the copying of private GitHub repositories and exposed limited user and investor information.
Researchers have uncovered a supply chain attack targeting AI agents through trojanized skills that accumulated over 1.7 million installs and deployed credential stealing malware from GitHub.
Hugging Face has disclosed a cyberattack carried out by an autonomous AI agent that accessed internal datasets and credentials but did not affect public models or software supply chain.
Researchers have uncovered a supply chain attack targeting the Mastra npm ecosystem, where more than 140 packages were compromised through a hijacked contributor account and a malicious dependency designed to steal cryptocurrency wallet data and sensitive credentials.
Microsoft adds a two hour delay for automatic VS Code extension updates to reduce supply chain attacks while allowing immediate updates for trusted publishers.
Cybersecurity researchers have uncovered IronWorm and a new Miasma worm variant targeting npm packages, stealing developer credentials and spreading malware through software supply chain attacks.
Cybersecurity researchers have uncovered a supply chain attack involving the codexui-android npm package, exposing OpenAI Codex authentication tokens through a malicious exfiltration mechanism affecting developers and Android app users.
OpenAI confirms a supply chain attack linked to malicious TanStack packages compromised two employee devices and exposed limited credential material from internal repositories.
NCERT has issued a high-priority advisory after hackers compromised trusted software packages like debug, chalk, ansi-styles, and stripansi, putting global systems at risk.