A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems ...
JavaScript向けパッケージ管理サービス「npm」で、広く使われている数百個のパッケージに認証情報を盗むマルウェアが混入される大規模なサプライチェーン攻撃が発生しました。セキュリティ企業のAikido ...
ChainDrop contaminó 435 paquetes y 1,557 versiones; robó credenciales pese a publicar con atestaciones SLSA válidas.
DOUBLECUP hides malware stages in cached PNG files, then uses ClickFix commands to deliver CountLoader variants and the ...
SMOKE#SCREEN uses fake Adobe and Zoom updates, document lures, and trusted cloud services to install ScreenConnect for persistent remote access.
Open VSX marketplace impersonated legitimate developer tools while transmitting information about the systems and development ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results