Tag
Attackers compromised the GitHub account of the maintainer behind keyv and related npm caching libraries, injecting a credential-stealing worm across multiple packages with over 2 billion combined monthly installs.
CrowdStrike has discovered a worm that targets AI software supply chains, stealing credentials and performing destructive actions while evading detection by mimicking legitimate AI coding activities.
Nationwide emergency response today because AntV, an open-source frontend library by Ant Group, was hit by a supply chain attack and implanted with a worm. Users need to urgently check and upgrade.
A PSA about a series of supply-chain attacks targeting AI developer tools (Hermes, OpenClaw) via npm and PyPI, specifically the 'Mini-Shai Hulud' worm that self-replicates and steals credentials, API keys, and browser sessions. The post advises sandboxed execution and restricting package age to mitigate risks.