Introducing SafeDep Threat Intel
SafeDep has launched SafeDep Threat Intel, an add-on to any paid plan that provides SOC and cyber defense teams with a malicious package feed API and a Threat Intel Dashboard, covering npm, PyPI, Go, …
SafeDep has launched SafeDep Threat Intel, an add-on to any paid plan that provides SOC and cyber defense teams with a malicious package feed API and a Threat Intel Dashboard, covering npm, PyPI, Go, …
The jscrambler npm package was backdoored five times in three hours on July 11, 2026, after a threat actor stole an npm publishing credential. The malicious versions (8.14.0–8.20.0, excluding 8.15.0) …
A malicious version of the npm package jscrambler used a preinstall hook to deploy a Rust infostealer on developer machines. The attack targeted browser credentials, crypto wallets, and Bitwarden vaul…
A developer detailed three vulnerabilities in the AI-coding-agent stack, including a supply chain worm that persists in developer toolchain configs, an abuse of shell built-ins to bypass Cursor's comm…
In June 2026, attackers hijacked the npm contributor account 'ehindero' to mass-publish malicious versions of 144 packages under the @mastra namespace, in what security researchers from JFrog, SafeDep…
Eight days after the Miasma worm injected a 4.3 MB credential stealer into public GitHub repositories, 123 repositories across 56 accounts still carry the live dropper on 665 branches, according to a …
A malicious npm package called `js-logger-pack` evolved through 29 versions into a full remote access trojan (RAT) named `MicrosoftSystem64` that exfiltrates stolen data to attacker-controlled Hugging…
Gergely Orosz reports that AI is amplifying team culture for better or worse, while Cloudflare demonstrates frontier models chaining exploits and outperforming single-agent verification in security re…
A malicious npm package called `js-logger-pack` evolved through 29 versions on the registry from April 2026 into a full remote access trojan that deploys an 81 MB binary named `MicrosoftSystem64` on W…
Five typosquatting npm packages published by accounts named "superbase" and "micresoft" contain a hidden 4.5 MB ELF binary that executes automatically upon `npm install` and, through a hijacked `Sessi…