Days after IBM and Red Hat announced a master security plan for open-source software, Red Hat suffers a major breach of its ...
Perplexity launches Bumblebee: How its new read-only dev scanner differs from Chainguard ...
GitHub’s internal repositories — now staged publishing in npm 11.15.0 requires a human 2FA approval before any package goes ...
TrapDoor spread 34 malicious packages across npm, PyPI, and Crates.io, stealing developer credentials and enabling persistence.
Official Red Hat NPM accounts have been compromised and used to push a malicious worm that spreads from machine to machine, ...
GitHub has rolled out new controls for npm to improve the security of the software supply chain, giving maintainers the ...
A dependency confusion campaign leveraged 33 malicious npm packages to collect reconnaissance data from developer and build environments. This report details the attack chain, observed tradecraft, and ...
The OWASP-backed tool scans JavaScript and TypeScript lockfiles locally, aiming to help developers catch and remediate dependency risks before CI failures.
Popular JavaScript modules including size-sensor and echarts-for-react hit as hijacked account closed GitHub warnings ...
The world’s largest open-source registry, node package manager (npm), has been hit by another fast-moving malware attack, this time targeting the widely-used AntV enterprise data visualization tool.