The workflow is disguised as a security improvement and exfiltrates two categories of data to a hardcoded IP address over plain HTTP: the repository's named GitHub Actions secrets, and every cloud, AI ...
@bitwarden/cli@2026.4.0 — the official command-line interface for the Bitwarden password manager — was found compromised on npm. A malicious preinstall hook silently bootstraps the Bun JavaScript ...
AI agent skills live in two places. Developers install them on their own machines, and teams commit them to repositories so everyone who works in the codebase gets them. A skill often travels between ...
Several packages in the @redhat-cloud-services npm scope were found to carry malicious payloads that fire via a preinstall hook on every npm install. The affected versions span multiple packages ...
All release tags in the Checkmarx/kics-github-action repository have been compromised with an infostealer payload. If you are using this Action pinned to any version tag, treat your CI/CD secrets as ...
On October 5, 2026, StepSecurity analyzed @subql/common@5.8.3 on npm and identified a hidden payload that collects credentials and supports remote shell access. It starts during installation and when ...
The malicious release was built from the project's own main branch and published with an npm provenance attestation. On October 5, 2026, StepSecurity analyzed @subql/common@5.8.3 on npm and identified ...
What we tried before We relied on native GitHub Actions controls plus our own conventions, action pinning, permission scoping, and code review. Those are a strong baseline, but by design they're ...
Compromised MemTensor npm releases turn an AI memory plugin into a credential-harvesting entry point, exposing prompts and creating a path to further package compromise. Harden-Runner now secures ...
Malicious 2773 beta versions of @joyfill/components and @joyfill/layouts carry an obfuscated remote access trojan and credential stealer that run on import. Here is how it works and how to check if ...
A registry-only supply chain attack on @velora-dex/sdk delivers an architecture-aware macOS backdoor that fires the moment your code imports the package. No install hooks, no repo commits, no visible ...
Anthropic disclosed that a Claude model published a malicious package to PyPI during a cybersecurity evaluation. It ran on 15 real systems within an hour, including a security company's malware ...