cd /news/ai-safety/lone-attacker-published-14-malicious… · home topics ai-safety article
[ARTICLE · art-18306] src=theregister.com pub= topic=ai-safety verified=true sentiment=↓ negative

Lone attacker published 14 malicious npm packages mimicking popular OpenSearch, Elasticsearch libraries

A lone attacker published 14 malicious npm packages that mimicked popular OpenSearch and Elasticsearch libraries. Microsoft identified and removed the packages, which were designed to trick developers into downloading malware.

read4 min publishedMay 29, 2026

MOST POPULAR

EVENTS #

Overcoming the trade-offs in data sovereignty

What does data sovereignty actually mean for your network, which trade-offs are unavoidable? Learn more.

From Prompt to Exploit: How LLMs Are Changing API Attacks

Modern applications are API-driven, interconnected, and often over-permissioned, making them an ideal target for AI-assisted attacks.

Architecting the Future: Unlocking Enterprise Data Services for Kubernetes

Join us to discover how to eliminate infrastructure silos and establish a standardized, enterprise-grade cloud-native platform.

Catch the Advanced Attacks Microsoft 365 Misses with Behavioral AI Security

Microsoft 365 is the backbone of enterprise communication, and its native security filters out the known and the noisy.

Virtual Cyber Recovery Sim

Step into the chaos of a live ransomware breach, test your response skills, and team up with other IT and security pros to outsmart cybercriminals

Virtual Cyber Recovery Simulation

Ransomware attacks aren’t slowing down, and neither are we. Druva’s hit event, Escape Ransomware, is now fully virtual.

Agentic AI at Scale: From Pilot to Production

Join us to learn how to unlock real ROI by driving adoption of AI at scale.

AI #

AI + ML

AWS reportedly to tuck Elon Musk's Grok into Bedrock, despite zero enterprise demand

The energy drink of frontier models

Security

Lone attacker published 14 malicious npm packages mimicking popular OpenSearch, Elasticsearch libraries

And then Microsoft busted them all

ai + ml

Okta writes its own license to kill rogue AI agents

CEO Todd McKinnon says customers including ServiceNow want an off switch

public sector

ICE to keep an eye on your eyes under $25M biometric scanner deal

And you thought a face recognition app was intrusive?

Security

No fix yet for critical RCE bug in open-source Git service Gogs - exploit module is out

Researcher reported the vuln in March. Maintainers haven't responded to his messages since

Infosec #

AI + ML

AWS reportedly to tuck Elon Musk's Grok into Bedrock, despite zero enterprise demand

The energy drink of frontier models

Security

Lone attacker published 14 malicious npm packages mimicking popular OpenSearch, Elasticsearch libraries

And then Microsoft busted them all

ai + ml

Okta writes its own license to kill rogue AI agents

CEO Todd McKinnon says customers including ServiceNow want an off switch

public sector

ICE to keep an eye on your eyes under $25M biometric scanner deal

And you thought a face recognition app was intrusive?

Security

No fix yet for critical RCE bug in open-source Git service Gogs - exploit module is out

Researcher reported the vuln in March. Maintainers haven't responded to his messages since

FOSS #

AWS reportedly to tuck Elon Musk's Grok into Bedrock, despite zero enterprise demand

The energy drink of frontier models

Lone attacker published 14 malicious npm packages mimicking popular OpenSearch, Elasticsearch libraries

And then Microsoft busted them all

Okta writes its own license to kill rogue AI agents

CEO Todd McKinnon says customers including ServiceNow want an off switch

ICE to keep an eye on your eyes under $25M biometric scanner deal

And you thought a face recognition app was intrusive?

No fix yet for critical RCE bug in open-source Git service Gogs - exploit module is out

Researcher reported the vuln in March. Maintainers haven't responded to his messages since

QEMU mulls relaxing AI contribution ban

Red Hat engineer reckons the balance of risk has shifted, but core code stays off limits

FEATURES

Europe built sovereign clouds to escape US control. Then forgot about the processors

Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data

Europe wants out from under US tech – but first it has to find the exits

GNOME may rule Ubuntu Resolute Raccoon, but X.org isn't roadkill yet

OpenClaw, but in containers: Meet NanoClaw

Open source registries don't have enough money to implement basic security

Contain your Windows apps inside Linux Windows

The Linux mid-life crisis that's an opportunity for Tux-led transformation

Too much AI for some, too little for others: Why AMD can't win with investors

How agentic AI can strain modern memory hierarchies

── more in #ai-safety 4 stories · sorted by recency
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/lone-attacker-publis…] indexed:0 read:4min 2026-05-29 ·