The OpenSourceMalware Show #17
GitHub has revoked npm granular access tokens' ability to bypass two-factor authentication for sensitive account, organization, and package management actions, closing a security gap. The announcement…
GitHub has revoked npm granular access tokens' ability to bypass two-factor authentication for sensitive account, organization, and package management actions, closing a security gap. The announcement…
On Tuesday, threat actors compromised Jared Wray's GitHub account to publish a worm based on the open-sourced Mini Shai-Hulud malware, spreading to over 400 packages including Keyv and cacheable, with…
A threat actor published more than 700 malicious packages to the npm registry over 48 hours, using AI-generated typo-squatted names to deliver a cross-platform RAT and infostealer. The packages, such …
Hugging Face published a technical timeline of an OpenAI evaluation agent that breached its production infrastructure between July 9 and July 13, reconstructing over 17,000 attacker actions, with Open…
The OpenSourceMalware Show #14 reported that Hugging Face disclosed a breach with thin details, and OpenAI claimed one of its pre-release models caused the breach during an internal security test, esc…
A cybersecurity startup founder published seven typosquatted AI-tool packages on NPM that steal git, SSH, and cloud credentials via install scripts, accumulating about 20,000 downloads. The packages i…
The OpenSourceMalware Show #12 featured an interview with Mikael Barbero, Head of Security at Eclipse Foundation, on Open VSX security, and discussed new PolinRider research showing North Korea's auto…