A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems ...
keyv npm supply chain attack on August 4, 2026 let the Shai-Hulud worm compromise 400-plus packages and more than two billion ...
GitHub's supply chain defense map catalogs nine shipped controls across npm and GitHub Actions — covering pwn-request blocking, trusted publishing, staged publishing, and the Dependabot cooldown — ...
A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes malicious infrastructure harder to detect while ...
GitHub now automatically holds suspicious Actions workflows in public repositories, but maintainers must still review approvals, permissions, and risks.
The same GitHub event stream that organizations often treat as audit data can be used as behavioral telemetry to detect ...
GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact.
Latest update to Microsoft’s code editor improves dictation, introduces side chats, and adds support for comments to provide ...
A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory. The operation has been ...
Upwind identified a malicious release of keyv@6.0.0 that harvested AWS, GitHub, and npm credentials via a hidden preinstall script. With 154 million weekly downloads, the compromise had ecosystem-wide ...
New controls for model reasoning and Copilot code-review depth let developers decide how much AI effort a task warrants, with speed, depth and credit consumption all part of the tradeoff.