A hijacked GitHub account let the Shai-Hulud worm pass npm's trust check, spreading through packages with 2 billion monthly ...
Microsoft and Uno Platform have released the first stable versions in the SkiaSharp 4 series, beginning with SkiaSharp ...
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems ...
Open VSX marketplace impersonated legitimate developer tools while transmitting information about the systems and development ...
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by ...
GitHub's supply chain defense map catalogs nine shipped controls across npm and GitHub Actions — covering pwn-request ...
GitHub now automatically holds suspicious Actions workflows in public repositories, but maintainers must still review ...
Microsoft's July release adds a Copilot Chat agent preview, workload-specific skills, shared instructions, branch context and C++ build controls.