ClickFix attacks are delivering BabaDeda, Lorem Ipsum, and Potemkin loaders to deploy stealers, RATs, and ransomware-linked ...
July 2026, blocking install scripts, Git dependencies, and remote URL sources by default. Every team running npm install in ...
Mastra npm packages added easy-day-js malware, exposing developer systems and CI runners to infostealer risks.
Chrome's WebMCP guidance warns that AI agents can be manipulated through the tools they are built to trust.
The Miasma credential-stealing attack framework, which has recently targeted open-source ecosystems through supply-chain ...
Detection and analysis tools for the atomic-lockfile supply-chain attack on the Arch User Repository (AUR). This is a collection of all the scattered resources, especially the ones in the detection ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results