The popular Python package for monitoring data quality was briefly available as a malicious version. Provider Elementary ...
A stealthy Python-based backdoor framework capable of long-term surveillance and credential theft has been identified ...
Developers of major Linux distributions have begun shipping patches to address a local privilege escalation (LPE) ...
Open source software with more than 1 million monthly downloads was compromised after a threat actor exploited a ...
Multiple official SAP npm packages were compromised in what is believed to be a TeamPCP supply-chain attack to steal ...
An attacker pushed a malicious version of the popular elementary-data package Python Package Index (PyPI) to steal sensitive ...
Claude Opus commit added malicious npm dependency in Feb 2026, enabling crypto theft and persistent RAT access.
A new report from ReversingLabs identified a new tactic by North Korean hackers: feeding malicious code to the AI systems ...
Malicious npm packages have been identified distributing malware that steals credentials and attempts to spread across ...
This was not a case of stolen credentials, but rather of vulnerability exploitation.