Researchers found 15 malicious JetBrains plugins posing as AI coding tools that exfiltrate OpenAI, DeepSeek, and SiliconFlow ...
From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet
A poisoned npm package infected 140+ projects with a hidden payload. This report highlights how to detect, hunt, and defend ...
A coalition including Google, Microsoft, and GitHub published Agentic Resource Discovery, an open draft spec for how AI ...
A single pipeline replaced fourteen lines and I never looked back.
Microsoft Threat Intelligence analyzed a cryptocurrency clipper campaign that combines clipboard theft, wallet replacement, ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results