cd/entity/SafeDep· home entities SafeDep
grep -l @safedep /news/*.json | wc -l → 9

SafeDep

mentions 9 type Organization feed RSS

// recent coverage 9 mentions

21:14
2026-07-12
byteiota.com
ai-tools

jscrambler npm Backdoored: Rotate Your Credentials Now

The jscrambler npm package was backdoored five times in three hours on July 11, 2026, after a threat actor stole an npm publishing credential. The malicious versions (8.14.0–8.20.0, excluding 8.15.0) …

12:02
2026-07-12
dev.to
ai-safety

How a preinstall hook silently ran malware on npm install

A malicious version of the npm package jscrambler used a preinstall hook to deploy a Rust infostealer on developer machines. The attack targeted browser credentials, crypto wallets, and Bitwarden vaul…

14:16
2026-06-17
dev.to
ai-agents

I Gave Claude Code the Keys. So Did a Worm.

A developer detailed three vulnerabilities in the AI-coding-agent stack, including a supply chain worm that persists in developer toolchain configs, an abuse of shell built-ins to bypass Cursor's comm…

10:00
2026-06-11
safedep.io
ai-agents

Miasma Worm: Most Infected GitHub Repos Are Still Live

Eight days after the Miasma worm injected a 4.3 MB credential stealer into public GitHub repositories, 123 repositories across 56 accounts still carry the live dropper on 665 branches, according to a …

10:14
2026-05-29
safedep.io
ai-safety

A Supply Chain Rat Exfiltrating to HuggingFace

A malicious npm package called `js-logger-pack` evolved through 29 versions into a full remote access trojan (RAT) named `MicrosoftSystem64` that exfiltrates stolen data to attacker-controlled Hugging…

06:36
2026-05-29
dev.to
ai-agents

Supply Chains, Zombie OSS, and Agent Firewalls

Gergely Orosz reports that AI is amplifying team culture for better or worse, while Cloudflare demonstrates frontier models chaining exploits and outperforming single-agent verification in security re…

12:00
2026-05-13
safedep.io
cybersecurity

Malicious npm Packages Backdoor Claude Code Sessions

Five typosquatting npm packages published by accounts named "superbase" and "micresoft" contain a hidden 4.5 MB ELF binary that executes automatically upon `npm install` and, through a hijacked `Sessi…

// co-occurs with top 8 entities
// topics top 6 topics