infosec

Threat campaign fooling developers in GitHub repos

A threat campaign has been targeting software developers through GitHub repos that, at first glance, look completely legitimate. Security researchers…

5 days ago

JavaScript packages hide ‘protestware’ against Russian users

Security researchers from Socket have stumbled upon a digital booby trap set for Russian-language users within JavaScript packages. The researchers…

6 days ago

Future of development or risky shortcut?

So-called “vibe coding” is both exciting and a little unnerving—it’s a shift away from the painstaking, line-by-line grind of traditional…

1 week ago

Veracode unravels 12-layer npm attack to find RAT

Security researchers at Veracode, during their routine monitoring of the open-source world, stumbled upon two seemingly harmless software packages on…

2 weeks ago

Package lurking in npm for six years waits to destroy your work

Socket’s threat researchers have uncovered a package lurking in npm for six years that awaits a remote command to wipe…

4 weeks ago