The GlassWorm supply-chain campaign has returned with a new, coordinated attack that targeted hundreds of packages, ...
How can an extension change hands with no oversight?
ClickFix campaigns spread MacSync macOS infostealer via malicious Terminal commands since Nov 2025, targeting AI tool users ...
New attack waves from the 'PhantomRaven' supply-chain campaign are hitting the npm registry, with dozens of malicious packages that exfiltrate sensitive data from JavaScript developers.