cd/sources/safedep-auto-discovered· home sources Safedep (auto-discovered)
cat /sources/safedep-auto-discovered.feed | wc -l → 17

Safedep (auto-discovered)

articles 17 domain safedep.io → feed RSS
00:00
2026-06-12
safedep.io
ai-safety

astro.config.mjs Supply Chain Attack via Blockchain C2

A supply chain attack targeting the open-source tool Understand-Anything (57,000+ GitHub stars) hid an obfuscated payload in `homepage/astro.config.mjs` via pull request #206, which executes automatic…

10:00
2026-06-11
safedep.io
ai-agents

Miasma Worm: Most Infected GitHub Repos Are Still Live

Eight days after the Miasma worm injected a 4.3 MB credential stealer into public GitHub repositories, 123 repositories across 56 accounts still carry the live dropper on 665 branches, according to a …

10:00
2026-06-09
safedep.io
ai-tools

Inside the Miasma Software Supply Chain Attack Toolkit

The Miasma software supply chain attack toolkit has been released as open source across multiple GitHub repositories, likely through compromised developer accounts. The toolkit enables attackers to ex…

10:00
2026-06-06
safedep.io
ai-agents

Config Files That Run Code: Supply Chain Security Blindspot

A single unsigned commit to the `icflorescu/mantine-datatable` repository added six files, five of which serve as launchers that execute a 4.3 MB dropper at `.github/setup.js`. The dropper, obfuscated…

10:00
2026-06-05
safedep.io
ai-agents

Miasma Worm Targets AI Coding Agents via GitHub Repos

On June 3, 2026, attackers pushed malicious commits to the GitHub repository `icflorescu/mantine-datatable` and four sibling repos, planting a 4.3 MB payload from the Miasma worm family. The commit ad…

10:14
2026-05-29
safedep.io
ai-safety

A Supply Chain Rat Exfiltrating to HuggingFace

A malicious npm package called `js-logger-pack` evolved through 29 versions into a full remote access trojan (RAT) named `MicrosoftSystem64` that exfiltrates stolen data to attacker-controlled Hugging…

03:21
2026-05-21
safedep.io
ai-agents

Polymarket npm Packages Steal Crypto Wallet Keys

Nine malicious npm packages impersonating Polymarket trading tools were published on May 20, 2026, by the account "polymarketdev," stealing cryptocurrency wallet private keys upon installation. The pa…

12:00
2026-05-13
safedep.io
cybersecurity

Malicious npm Packages Backdoor Claude Code Sessions

Five typosquatting npm packages published by accounts named "superbase" and "micresoft" contain a hidden 4.5 MB ELF binary that executes automatically upon `npm install` and, through a hijacked `Sessi…

00:00
2026-05-11
safedep.io
ai-tools

Endpoint Protection for Developer Machines

SafeDep has released PMG, an open-source package guard that intercepts npm, pip, and cargo installs to block malicious packages before their post-install scripts execute. The tool, which can be synced…

10:00
2026-05-03
safedep.io
ai-safety

node-env-resolve: npm Package Installs a Full RAT

The malicious npm package `node-env-resolve`, disguised as a lightweight environment configuration resolver, installs a full remote access trojan (RAT) on victim machines upon execution of `npm instal…

00:00
2026-05-01
safedep.io
ai-tools

exiouss: Cookie Stealer Bundled in npm Exam Cheat

A malicious npm package named "exiouss" was published on May 1, 2026, by the account "loltestpad" as a rebranded version of the previously removed "godsplan" package, now bundling a PowerShell script …

12:00
2026-04-30
safedep.io
cybersecurity

PyTorch Lightning Compromised: Shai-Hulud Worm Reaches PyPI

The PyTorch Lightning deep-learning framework was compromised on PyPI, with versions 2.6.2 and 2.6.3 containing a credential-stealing worm called Shai-Hulud. The malware activates when Python code run…

00:00
2026-04-16
safedep.io
cybersecurity

ixpresso-core: Windows RAT Disguised as a WhatsApp Agent

"ixpresso-core," a malicious Windows Remote Access Trojan (RAT) published on npm and disguised as a WhatsApp-integrated AI agent. Once installed, it deploys persistent malware called "Veltrix" that st…