cd/entity/SafeDep· home entities SafeDep
grep -l @safedep /news/*.json | wc -l → 4

@SafeDep

mentions 4 type Organization feed RSS
10:14
2026-05-29
safedep.io
ai-safety

A Supply Chain Rat Exfiltrating to HuggingFace

A malicious npm package called `js-logger-pack` evolved through 29 versions into a full remote access trojan (RAT) named `MicrosoftSystem64` that exfiltrates stolen data to attacker-controlled Hugging…

06:36
2026-05-29
dev.to
ai-agents

Supply Chains, Zombie OSS, and Agent Firewalls

Gergely Orosz reports that AI is amplifying team culture for better or worse, while Cloudflare demonstrates frontier models chaining exploits and outperforming single-agent verification in security re…

12:00
2026-05-13
safedep.io
cybersecurity

Malicious npm Packages Backdoor Claude Code Sessions

Five typosquatting npm packages published by accounts named "superbase" and "micresoft" contain a hidden 4.5 MB ELF binary that executes automatically upon `npm install` and, through a hijacked `Sessi…

// co-occurs with top 8 entities