SAP npm packages poisoned on April 29, 2026 + AES-256-GCM encrypted credential theft + AI coding tools abused for spread.
Fake OpenAI Privacy Filter hit #1 on Hugging Face with 244,000 downloads, spreading infostealer malware to Windows users.
The wave of supply chain attacks aimed at security and developer tools has washed up more victims, namely SAP and Intercom ...
A malicious version of the PyTorch Lightning package published on the Python Package Index (PyPI) delivers a ...
Multiple SAP npm packages were compromised in a supply chain attack designed to steal developer credentials and tokens.
A new wave of the Glassworm campaign is targeting the OpenVSX ecosystem with 73 "sleeper" extensions that turn malicious ...
A threat group planted a malicious npm package in a crypto trading project through an AI-generated commit by Anthropic's ...
UNC6692 relies on email bombing and social engineering to infect victims with Snow malware: Snowbelt, Snowglaze, and ...
The threat actor seeding the Open VSX code marketplace with fraudulent extensions that download the GlassWorm malware has ...
ClickFix relies on tricking users into essentially hacking themselves by running commands that compromise their computers. In ...
The attacks compromise aerospace and drone firms' systems to exfiltrate GIS files, terrain models, and GPS data to gain a clear picture of analysts' intel.
Cybercriminals are increasingly relying on social engineering instead of traditional exploits, and Australian authorities are ...