keyv npm supply chain attack on August 4, 2026 let the Shai-Hulud worm compromise 400-plus packages and more than two billion ...
A Keyv-linked npm worm poisoned 353 versions across 79 package names, stealing developer and CI credentials while repository ...
A massive supply chain attack on the Node Package Manager (npm) registry has infected over 400 packages with over 2 billion downloads with the ...
More than 400 NPM packages have been infected with the Mini Shai-Hulud worm in the ChainDrop supply chain attack.
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems ...
Aikido Security says an npm supply chain attack has infected Keyv packages with a variant of the credential-stealing ...
Typosquatting on popular AI services Paperclip and Browser Use, the malicious skills cracked skills.sh’s trending list, ...
Maybe feeling left out from the questionable hype train of “Our AI models can’t be trusted”, Anthropic has released reports that their Claude model has “reached the ...
Dependency confusion is a supply chain issue that affects how package managers choose where to download a dependency from. If your build or developer tooling can see both a private package registry ...
Gemini CLI and Claude Code flaws let untrusted GitHub input reach CI workflows, including host command execution and API key ...
The Shai Hulud variant’s blast radius includes several highly popular packages thus far.. Security teams are urged to perform ...
A Mini Shai-Hulud worm spread through more than 400 npm packages, stealing npm, GitHub, cloud, and CI/CD credentials.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results