Packagist packages hid malicious package.json scripts, enabling Linux binary execution during installs and workflows.
A GitHub employee installed a routine VS Code extension update, handed cybercrime group TeamPCP enough access to exfiltrate ...
The $10 million THORChain exploit was caused by a vulnerability in its GG20 signing framework, which allowed the hacker to ...
Reported over three years ago and allegedly still not properly fixed, the vulnerability enables attacks to execute JavaScript ...
Google has accidentally leaked details about an unfixed issue in Chromium that keeps JavaScript running in the background ...
GitHub is just the latest victim of TeamPCP, a gang that has carried out a spree of software supply chain attacks that has impacted hundreds of organizations.
GitHub says the hackers who breached 3,800 internal repositories gained access via a malicious version of the Nx Console VS ...
The Shai-Hulud campaign continues, now affecting hundreds of new packages and potentially compromising thousands of projects.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results