Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

Google News
stepsecurity.io > blog > 7nohe-openapi-react-query-codegen-compromised-npm-publishing-workflow

@7nohe/openapi-react-query-codegen Compromised Through an Exposed npm Publishing Workflow

2+ week, 2+ day ago   (602+ words) The attacker did not need a maintainer npm password or a long lived npm token. The repository accepted an npm publish comment from any pull request participant, checked out that pull request, installed its dependencies, and published packages with a…...

DigitalShield
escudodigital.com > en > cybersecurity > self-replicating-worm-compromises-over-400-critical-global-software-components.html

Self-replicating worm compromises over 400 critical global software components

1+ mon, 1+ week ago   (411+ words) Microsoft detects a computer worm that stealthily executes during routine software downloads, harvests server access credentials, and clones itself into victims' projects. Microsoft Threat Intelligence's cybersecurity team, the threat intelligence division of the Redmond firm, has issued a global alert…...

4sysops
4sysops.com > archives > chaindrop-npm-worm-now-targets-ci-cd-oidc-tokens-and-developer-tools

ChainDrop npm worm now targets CI/CD OIDC tokens and developer tools – 4sysops

1+ mon, 1+ week ago   (25+ words) ChainDrop is more than a malicious npm package outbreak: its worm can steal CI/CD credentials, abuse GitHub Actions OIDC publishing access, and plant persistenc...

SecurityWeek
securityweek.com > over-400-npm-packages-infected-in-chaindrop-supply-chain-attack

Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack

1+ mon, 1+ week ago   (615+ words) The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials. More than 2,200 malicious versions of 440 packages were published to the NPM registry as part of a fresh Mini Shai-Hulud supply chain…...

wiz.io
wiz.io > blog > keyv-and-cacheable-npm-supply-chain-attack

keyv and cacheable npm Package Hijacked in Supply Chain Attack | Wiz Blog

1+ mon, 1+ week ago   (224+ words) Wiz Research is actively investigating an ongoing software supply chain attack affecting multiple keyv/cacheable npm packages. August 4, 2026, 1345 UTC update: Many additional packages have been compromised, see the full list over on our GitHub. Wiz identified the user-agent Bun/1.3.13 performing…...

Google News
latesthackingnews.com > 07/26/2026 > cursor-git-exe-vulnerability > amp

Cursor's Unpatched Zero-Day Lets a Fake git.exe Hijack Any Windows Developer - Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses

1+ mon, 2+ week ago   (739+ words) A Cursor git.exe vulnerability lets a single renamed file hijack any Windows machine running the popular AI coding tool. Seven months after a researcher reported it, there is still no fix. AI security firm Mindgard published full technical details…...

GameLuster
gameluster.com > meccha-chameleon-malware-workshop-discord-breach

Meccha Chameleon Malware: Workshop & Discord Breach

1+ mon, 2+ week ago   (379+ words) GameLuster Meccha Chameleon, the indie breakout that has already sold over 15 million copies in 2026, confirmed on July 25 that malware was distributed through multiple Steam Workshop community maps and that its official Discord server was separately compromised, Meccha Chameleon has become…...

Coinfomania
coinfomania.com > malicious-npm-packages-detected-impacting-defi-developers-and-users

Malicious npm Packages Detected, Impacting DeFi Developers and Users

1+ mon, 2+ week ago   (250+ words) MistEye alerts users about a supply-chain attack targeting npm packages used in DeFi. Here's why developers need to act fast. MistEye detects a coordinated npm supply-chain attack on DeFi users. 30 malicious npm packages deliver JavaScript infostealers to developers. Developers urged…...

Coinfomania
coinfomania.com > security-alert-npm-supply-chain-attack-could-compromise-systems

Security Alert: npm Supply Chain Attack Could Compromise Systems

1+ mon, 2+ week ago   (139+ words) A coordinated npm supply chain attack affects 140+ packages. Users must act quickly to avoid compromise — here's what to do. npm supply chain attack targets over 140 packages, raising security concerns. Malicious code could lead to credential exposure and data exfiltration. Users…...

Coinfomania
coinfomania.com > security-alert-red-hat-cloud-services-npm-package-poisoning-uncovered

Security Alert: Red Hat Cloud Services npm Package Poisoning Uncovered

1+ mon, 2+ week ago   (59+ words) Red Hat Cloud Services faces a serious security breach involving npm packages. Here's why users should be concerned. Red Hat Cloud Services is facing a significant security threat. 32 npm packages were found with malicious loaders. The malware variant has advanced…...