Menu

#Malicious

68 posts

Feed·
20 of 68 posts
Malicious npm Package ua-parser-js2 Steals SSH Keys and Credentials via Typosquatting
🖼️
0

Malicious npm Package ua-parser-js2 Steals SSH Keys and Credentials via Typosquatting

WebProNews·Victoria Mossi·3 days ago
#84ktL32K

A malicious npm package called ua-parser-js2 impersonated the legitimate ua-parser-js library to steal sensitive files, environment variables, SSH keys, and credentials from developer machines via a post-install script.…

15s
Read More
📰
0

Supply Chain Compromises Impact Nx Console and GitHub Repositories | CISA

Cybersecurity and Infrastructure Security Agency CISA·US-CERT·4 days ago
#gHSmNqxG

CISA urges organizations to implement these recommendations to detect and remediate a potential compromise:

15s
Read More
Hackers used faked Apple & Yahoo infrastructure to hide malware
🖼️
0

Hackers used faked Apple & Yahoo infrastructure to hide malware

AppleInsider·Andrew Orr·18 days ago
#ynClkTiD

Hackers spent months hiding malware behind fake Apple-themed internet infrastructure and similarly bogus Windows pop-ups to infiltrate organizations across the Asia-Pacific region without triggering obvious security alarms. Here's how they did it.

15s
Read More
TanStack Was Not the Whole Story: Mini Shai-Hulud Was an npm/PyPI Supply-Chain Worm
🖼️
0

TanStack Was Not the Whole Story: Mini Shai-Hulud Was an npm/PyPI Supply-Chain Worm

DEV Community·Teruo Kunihiro·20 days ago
#nuInJIyz
#pypi#comment#security#npm#tanstack#github

How the TanStack npm compromise fits into the broader Mini Shai-Hulud campaign across npm, PyPI, GitHub Actions, IDE hooks, and CI/CD secrets.

15s
Read More
Compromised Mistral AI and TanStack packages may have exposed GitHub, cloud and CI/CD credentials in 'mini Shai Hulud'  malware infection — supply-chain campaign spreads across npm and AI developer ecosystems like wildfire
🖼️
0

Compromised Mistral AI and TanStack packages may have exposed GitHub, cloud and CI/CD credentials in 'mini Shai Hulud'  malware infection — supply-chain campaign spreads across npm and AI developer ecosystems like wildfire

From Latest from Tom's Hardware: Compromised Mistral AI and TanStack packages may have exposed GitHub, cloud and CI/CD credentials in 'mini Shai Hulud' malware infection — supply-chain campaign spreads across npm and AI developer ecosystems like wildfire

15s
Read More
Is Your Claude Code Safe From Base64? Inside 2026 AI Agent Attacks
🖼️
0

Is Your Claude Code Safe From Base64? Inside 2026 AI Agent Attacks

DEV Community·灯里/iku·22 days ago
#xMTIhKEB
#case#example#security#comments#base64#code

Is your Claude Code safe? Six months after befriending Base64, I keep finding them in shady places: hidden in supply chain attacks, MCP exploits, and AI agent compromises. A 2026 misuse tour for developers.

15s
Read More