Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ...
npm granular access tokens configured to bypass 2FA can no longer create tokens, change maintainers, or manage org membership as of July 31, 2026 — closing the attack chain TeamPCP exploited across ...
AWS Links Npm Attacks To North Korean Hackers Arabian Post. clearfix>Amazon Web Services has attributed a series of compromises involving widely used npm software packages, including Axios, Debug and ...
A DPRK-linked threat actor has been tied to four separate compromises of widely used JavaScript libraries since March 2025, ...
Arch Linux AUR malware has forced an emergency adoption freeze after Wave Three of the Atomic Arch campaign deployed a ...
The top AI coding tools are remarkably consistent in their hallucinations: Researcher Aleksandr Churilov found the same 127 ...
Researchers say Sapphire Sleet socially engineered maintainers before publishing malicious updates through trusted accounts ...
The cloud computing giant said in a blog post on July 29 that compromises of the axios, debug, chalk and typo-crypto libraries were carried out by the same group, known as Saphire Sleet, BlueNoroff ...
GitHub Actions will hold potentially malicious workflows until a collaborator with write access approves them.
Amazon threat researchers found one threat actor behind four distinct open source compromises, including the March 2026 ...
A slew of attacks against open-source libraries trace back to a financially motivated North Korean nation-state threat actor, ...