One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security ...
According to new research from Blackpoint Cyber's Adversary Pursuit Group (APG), published on July 30, the intrusion hit two ...
Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly ...
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems ...
HollowFrame and Matryoshka use DLL side-loading and GitHub C2 to gain a persistent foothold on two law firm endpoints.
Aikido Security says an npm supply chain attack has infected Keyv packages with a variant of the credential-stealing ...
keyv npm supply chain attack on August 4, 2026 let the Shai-Hulud worm compromise 400-plus packages and more than two billion ...
The Shai Hulud variant’s blast radius includes several highly popular packages thus far.. Security teams are urged to perform ...