Cybercrime | News, how-tos, features, reviews, and videos
Explore related topics
Report from Wiz also says developers are uploading extensions that include access tokens and other secrets.
A newly-discovered malicious package with layers of obfuscation is disguised as a utility library, with malware essentially hiding in plain sight in embedded QR codes.
Process improvements and a closer look at funding streams will provide far more protection for the open source software we depend on than isolated guardrails.
Scheduled for rollout starting in September 2026, the program aims to restrict malware distribution by requiring developer verification for apps installed on Android devices.
Phishing attacks on package maintainer accounts led to infected JavaScript type testing utilities.
Attackers use typo-squatting, obfuscation, and fake accounts to slip Python-based malware into open-source projects, raising fresh alarms for OSS supply chain security.
“Chimera-sandbox-extensions” exploit highlights rising risks of open-source package abuse, prompting calls for stricter dependency controls and DGA malware detection.
Malicious extensions that install a cryptominer were released just as the weekend started.
CISA confirms cascading attack from reviewdog to tj-actions exposed sensitive credentials across 23,000+ repositories.
Researchers say compromised tool in the GitHub CI/CD environment stole credentials; infosec leaders need to act immediately.