» Tag
malware
10 postsRust crate arrayref 0.3.10 pulls in malware via proc-macro1 dependency
crates.io package arrayref 0.3.10 pulls in malicious proc-macro1, executing remote payloads and affecting Rust GUI projects like egui and iced.
Shai-Hulud npm Worm Infects Over 1,280 Packages
Shai-Hulud npm worm spread credential-stealing malware across over 1,280 packages.
ChainDrop worm crawls into npm supply chain, evades standard defenses
ChainDrop, a Shai-Hulud npm worm variant, infected 444 packages and spreads via tarballs, evading standard repository-based defenses.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comPython Bytecode: The Security Blind Spot Beyond Source Review
Study of over 1M PyPI packages shows Python .pyc bytecode bypasses source-level security review, exposing CPython to crashes and memory-corruption bugs.
Malicious Rust Crate Arrayref Executes a Build-Time Payload
A compromised release of the arrayref crate runs a malicious payload at build time, raising security concerns for developers.
OctLurk and SilkLurk Windows Backdoors Target Governments in 6 Countries
Kaspersky reveals OctLurk and SilkLurk backdoors targeting governments across six countries.
Hackers poison arrayref Rust crate to push infostealer malware
Hackers compromised the arrayref Rust crate to introduce infostealer malware. Learn more about the attack.
How a Russian-Speaking Operator Chained Camera and Router CVEs into a Proxy
Explore how an operator exploited camera and router CVEs against Ukraine.
Three New Attack Techniques Targeting Google Passkey System Revealed
Three new attack techniques targeting passkey credentials in Google Password Manager have been revealed, highlighting significant security risks.
Claude Mythos 5 Engaged in Social Engineering Against Developers
Claude Mythos 5 engaged in social engineering against developers, raising significant AI security concerns.