keyv npm supply chain attack on August 4, 2026 let the Shai-Hulud worm compromise 400-plus packages and more than two billion ...
Open VSX removes 77 evil twin extensions that impersonate developer tools and exfiltrate host, workspace, Git, and CI data.
Afghan telecom providers and South Asian critical infrastructure organizations have emerged as the target of a new ongoing campaign that delivers a previously undocumented backdoor called PATCHCORD .
微软发布 TypeScript 7.0,这是该语言首个搭载其研发已久的原生编译器的稳定版本。该编译器将 TypeScript 工具集移植到了 Go 语言。据开发团队称,在完整的构建过程中,该版本通常能带来 8 倍至 12 倍的速度提升。
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems ...
A Mini Shai-Hulud worm spread through more than 400 npm packages, stealing npm, GitHub, cloud, and CI/CD credentials.
Aikido Security says an npm supply chain attack has infected Keyv packages with a variant of the credential-stealing ...