Install
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
@7nohe/openapi-react-query-codegen Compromised Through an Exposed npm Publishing Workflow
2+ week, 2+ day ago (602+ words) The attacker did not need a maintainer npm password or a long lived npm token. The repository accepted an npm publish comment from any pull request participant, checked out that pull request, installed its dependencies, and published packages with a…...
ChainDrop npm worm now targets CI/CD OIDC tokens and developer tools – 4sysops
1+ mon, 1+ week ago (25+ words) ChainDrop is more than a malicious npm package outbreak: its worm can steal CI/CD credentials, abuse GitHub Actions OIDC publishing access, and plant persistenc...
Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack
1+ mon, 1+ week ago (615+ words) The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials. More than 2,200 malicious versions of 440 packages were published to the NPM registry as part of a fresh Mini Shai-Hulud supply chain…...
keyv and cacheable npm Package Hijacked in Supply Chain Attack | Wiz Blog
1+ mon, 1+ week ago (224+ words) Wiz Research is actively investigating an ongoing software supply chain attack affecting multiple keyv/cacheable npm packages. August 4, 2026, 1345 UTC update: Many additional packages have been compromised, see the full list over on our GitHub. Wiz identified the user-agent Bun/1.3.13 performing…...
North Korean EtherHiding Campaign Targets Crypto Wallets and Developer Credentials
1+ mon, 1+ week ago (556+ words) A North Korean-linked cyber campaign is using fake macOS update screens to trick victims into installing malware. The operation targets cryptocurrency wallets, browser data, and developer credentials, turning a routine web search into a possible entry point for a serious…...
Meccha Chameleon Malware: Workshop & Discord Breach
1+ mon, 2+ week ago (379+ words) GameLuster Meccha Chameleon, the indie breakout that has already sold over 15 million copies in 2026, confirmed on July 25 that malware was distributed through multiple Steam Workshop community maps and that its official Discord server was separately compromised, Meccha Chameleon has become…...
Malicious npm Packages Detected, Impacting DeFi Developers and Users
1+ mon, 2+ week ago (250+ words) MistEye alerts users about a supply-chain attack targeting npm packages used in DeFi. Here's why developers need to act fast. MistEye detects a coordinated npm supply-chain attack on DeFi users. 30 malicious npm packages deliver JavaScript infostealers to developers. Developers urged…...
North Korea Hid New Google Drive Backdoors Inside South Korean Groupware Firms
1+ mon, 2+ week ago (548+ words) The hackers did not use a single entry point. In the first case, confirmed in November 2025, Kimsuky exploited a remote code execution vulnerability in an externally accessible mail server to install the Gomir backdoor. In the second, confirmed in December…...
Malicious NuGet Typosquat Targets Digitain Betting Platform and Rigs Game Results
1+ mon, 3+ week ago (466+ words) Unlike typical info-stealers that harvest credentials indiscriminately, this trojan functions as a fully operational JSON library for every host except its single intended target. The malicious package’s.nuspec metadata forged the identity of James Newton-King, pointed directly to the legitimate…...
New npm malware cluster targets Vite ecosystem
1+ mon, 3+ week ago (64+ words) SC Media New npm malware cluster targets Vite ecosystem (Credit: Araki Illustrations – stock.adobe.com) As outlined in The Hacker News, Checkmarx cybersecurity researchers have uncovered a new cluster of seven malicious npm packages, dubbed ViteVenom, that are specifically targeting…...