PowerShell Security: The Risk of `irm | iex`
The `irm | iex` PowerShell pattern, used by major projects like Bun and the Hugging Face CLI to install software, creates a security blind spot by executing remote code directly in memory without revi…
The `irm | iex` PowerShell pattern, used by major projects like Bun and the Hugging Face CLI to install software, creates a security blind spot by executing remote code directly in memory without revi…
A self-propagating malware strain called Sandworm_Mode is targeting AI coding assistants and software development environments, stealing credentials, API keys, and secrets across the AI toolchain, acc…
Cybersecurity firm CrowdStrike has identified a worm actively targeting AI toolchains to steal credentials, exfiltrate data, and destroy files, exploiting blind spots where malicious activity mimics l…
A teenage hacking group called TeamPCP poisoned two releases of LiteLLM, an open-source AI gateway tool downloaded 95 million times, stealing over 500,000 credentials and 300 GB of data from more than…
On March 24, 2026, attackers compromised LiteLLM's CI/CD pipeline and uploaded malicious PyPI packages that stole credentials from environments with three million daily downloads. The incident highlig…
A self-replicating worm called Miasma, attributed to threat actor TeamPCP, is targeting AI coding tools by injecting malicious hooks into configuration files of Claude Code, GitHub Copilot, Gemini CLI…
Security researcher found that several Claude Code community plugins listed in Anthropic's official marketplace were vulnerable to repo-jacking, where abandoned GitHub repository names could be claime…
Hackers are increasingly exploiting trusted developer tools rather than breaking into systems, with two major campaigns this week highlighting the trend. TeamPCP injected malicious code into over 1,00…
Tirith, a new terminal security tool, intercepts commands and pastes to detect homograph attacks, pipe-to-shell patterns, ANSI injection, credential leaks, and 200+ other threats in under 1ms. It cove…
A developer detailed three vulnerabilities in the AI-coding-agent stack, including a supply chain worm that persists in developer toolchain configs, an abuse of shell built-ins to bypass Cursor's comm…
PostHog co-founder James Hawkins warns that the fragmentation of coding interfaces—from Slack bots to AI agents and MCP servers—is expanding the attack surface on developer devices faster than securit…
GitHub disabled 73 repositories across four Microsoft organizations — Azure, Azure-Samples, Microsoft, and MicrosoftDocs — after the self-replicating Miasma worm planted malicious payloads that harves…
A new malware campaign dubbed 'Miasma' is spreading through IDE configuration settings, AI-assisted environments, and multiple package manager ecosystems, marking what researchers believe is the first…
A hacker group named TeamPCP has been conducting an unprecedented series of software supply chain attacks, poisoning hundreds of open source tools to extort victims. In the latest incident, the group …
On 20 May 2026, GitHub confirmed that approximately 3,800 internal repositories were exfiltrated after an employee installed a poisoned code editor extension that handed attackers credentials and clou…
The PyTorch Lightning deep-learning framework was compromised on PyPI, with versions 2.6.2 and 2.6.3 containing a credential-stealing worm called Shai-Hulud. The malware activates when Python code run…
A financially motivated cybercrime group called TeamPCP has launched a wiper attack targeting Iran, using a self-propagating worm named "CanisterWorm" that destroys data on systems set to Iran's time …