anti-slop: Opinionated Oxlint rules
Developer Dillon Mulroy released anti-slop, an open-source (MIT) plugin of opinionated Oxlint rules that reject low-evidence and low-signal TypeScript and JavaScript patterns, distributed via source a…
Developer Dillon Mulroy released anti-slop, an open-source (MIT) plugin of opinionated Oxlint rules that reject low-evidence and low-signal TypeScript and JavaScript patterns, distributed via source a…
A coding-agent security tool shipped by an unnamed developer was found to have three critical flaws, including a kill switch at `.claude/gate-off` that the agent could create without denial, allowing …
Socket, a supply-chain security scanner, flagged the npm package ai2rules-harness with a Supply Chain Security score of 64%, prompting its developer to discover that the package's postinstall script f…
Porcupine, a terminal AI agent built for safe autonomy, has been released as an open-source tool on GitHub, requiring Node.js 22.19+ and installable via npm. It offers Ask, Normal, and Auto modes to l…
A developer built Recall, a local CLI that derives structured context from a repository and stores it inside the repository itself, aiming to eliminate the need for coding agents to rediscover the rep…
OpenAI will retire its Assistants API on 26 August 2026, a year after the announcement, forcing developers to migrate to the Responses API. A developer's analysis of npm download data shows that 99% o…
Ruflo v3.35.0 fixes a dependency bug where MetaHarness packages were silently absent due to being declared as optional peer dependencies, and implements ADR-381 to cap false promotions in its self-opt…
On Tuesday, threat actors compromised Jared Wray's GitHub account to publish a worm based on the open-sourced Mini Shai-Hulud malware, spreading to over 400 packages including Keyv and cacheable, with…
Security firm Zenity discovered a campaign that trojanized AI agent skills to deploy a credential stealer, amassing over 1.7 million downloads by Aug. 2. The malicious skills, uploaded to skills.sh on…
Truffle Security CEO Dylan Ayrey and Socket CEO Feross Aboukhadijeh said AI models are already capable of executing sophisticated cyberattacks, including SQL injection and supply chain attacks, and th…
A threat actor published more than 700 malicious packages to the npm registry over 48 hours, using AI-generated typo-squatted names to deliver a cross-platform RAT and infostealer. The packages, such …
Wiz's Research and CIRT teams reported a 60% increase in significant cloud security incidents in H1 2026 compared to H2 2025, driven by a doubling of supply-chain attacks and new vulnerability disclos…
Aikido Security disclosed a critical npm supply chain attack dubbed ChainDrop, which compromised popular packages including keyv, flat-cache, and file-entry-cache. The attackers hijacked maintainer Gi…
Cloudrift, a read-only AWS waste scanner, is now available as a command-line tool that estimates monthly costs of wasted resources without modifying or deleting anything. The tool, installable via npm…
On March 31, 2026, Chaofan Shou discovered that Anthropic's Claude Code source code was exposed via a sourcemap file in the npm package, revealing the entire source code of the AI coding CLI. The leak…
Socket's Threat Research Team reported an active supply chain attack on August 4, 2026, that compromised the npm packages keyv and cacheable, affecting tens of millions of weekly downloads. The attack…
Snyk introduced Agentic AppSec with two new capabilities: Remediation Agent, now in public preview, and Malicious Code Defense, in private preview. The Remediation Agent automatically fixes vulnerabil…
The npm package keyv published version 6.0.0 on 4 August 2026 with a preinstall script that executes an obfuscated dropper, compromising any developer who installed it directly or as a transitive depe…
A developer released Yet Another OpenCode Plugin, an opencode plugin that adds terse response modes, a YAGNI-based 'lazy dev' ruleset, and two read-only agents (Review and Dream) to the opencode AI co…
Enterprises are facing three major AI security mistakes as AI agents move from pilots to production, according to an InfoWorld analysis. The mistakes include unvetted dependencies from package registr…