cd/sources/safedep-auto-discovered· home sources Safedep (auto-discovered)
cat /sources/safedep-auto-discovered.feed | wc -l → 14

Safedep (auto-discovered)

articles 14 domain safedep.io → feed RSS
10:00
2026-06-06
safedep.io
ai-agents

Config Files That Run Code: Supply Chain Security Blindspot

A single unsigned commit to the `icflorescu/mantine-datatable` repository added six files, five of which serve as launchers that execute a 4.3 MB dropper at `.github/setup.js`. The dropper, obfuscated…

10:00
2026-06-05
safedep.io
ai-agents

Miasma Worm Targets AI Coding Agents via GitHub Repos

On June 3, 2026, attackers pushed malicious commits to the GitHub repository `icflorescu/mantine-datatable` and four sibling repos, planting a 4.3 MB payload from the Miasma worm family. The commit ad…

10:14
2026-05-29
safedep.io
ai-safety

A Supply Chain Rat Exfiltrating to HuggingFace

A malicious npm package called `js-logger-pack` evolved through 29 versions into a full remote access trojan (RAT) named `MicrosoftSystem64` that exfiltrates stolen data to attacker-controlled Hugging…

03:21
2026-05-21
safedep.io
ai-agents

Polymarket npm Packages Steal Crypto Wallet Keys

Nine malicious npm packages impersonating Polymarket trading tools were published on May 20, 2026, by the account "polymarketdev," stealing cryptocurrency wallet private keys upon installation. The pa…

12:00
2026-05-13
safedep.io
cybersecurity

Malicious npm Packages Backdoor Claude Code Sessions

Five typosquatting npm packages published by accounts named "superbase" and "micresoft" contain a hidden 4.5 MB ELF binary that executes automatically upon `npm install` and, through a hijacked `Sessi…

00:00
2026-05-11
safedep.io
ai-tools

Endpoint Protection for Developer Machines

SafeDep has released PMG, an open-source package guard that intercepts npm, pip, and cargo installs to block malicious packages before their post-install scripts execute. The tool, which can be synced…

10:00
2026-05-03
safedep.io
ai-safety

node-env-resolve: npm Package Installs a Full RAT

The malicious npm package `node-env-resolve`, disguised as a lightweight environment configuration resolver, installs a full remote access trojan (RAT) on victim machines upon execution of `npm instal…

00:00
2026-05-01
safedep.io
ai-tools

exiouss: Cookie Stealer Bundled in npm Exam Cheat

A malicious npm package named "exiouss" was published on May 1, 2026, by the account "loltestpad" as a rebranded version of the previously removed "godsplan" package, now bundling a PowerShell script …

12:00
2026-04-30
safedep.io
cybersecurity

PyTorch Lightning Compromised: Shai-Hulud Worm Reaches PyPI

The PyTorch Lightning deep-learning framework was compromised on PyPI, with versions 2.6.2 and 2.6.3 containing a credential-stealing worm called Shai-Hulud. The malware activates when Python code run…

00:00
2026-04-16
safedep.io
cybersecurity

ixpresso-core: Windows RAT Disguised as a WhatsApp Agent

"ixpresso-core," a malicious Windows Remote Access Trojan (RAT) published on npm and disguised as a WhatsApp-integrated AI agent. Once installed, it deploys persistent malware called "Veltrix" that st…