The type confusion bug can lead to V8 sandbox escape and control-flow hijacking of the host process. A critical-severity type ...
keyv npm supply chain attack on August 4, 2026 let the Shai-Hulud worm compromise 400-plus packages and more than two billion ...
China-linked Jewelbug uses XG-Web for espionage and crypto fraud, stealing over 580,000 browser cookies and thousands of ...
Six npm packages have been found querying an attacker-controlled Ethereum wallet to work out where to fetch their next stage of malware, reading command-and-control (C2) addresses out of a blockchain ...
Another Shai-Hulud variant hits npm packages, worming its way into hundreds of packages.
Threat actors are using fully functional productivity applications to deliver Projextor malware through the same Electron ...
Researchers assess the activity as China-nexus with medium confidence, citing victim selection, shared malware tooling, ...
Spread the love“`html If you’re a developer, or even just someone who dabbles in code, chances are you’ve spent a fair bit of ...
Spread the love“`html Visual Studio Code, or VS Code as it’s affectionately known, has become the undisputed heavyweight ...
The type confusion vulnerability allows a guest-to-host sandbox escape which can lead to remote code execution ...
A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory. The operation has been ...
Upwind was the first to publicly report that [email protected], a widely used npm package with 154 million weekly downloads, contained a malicious preinstall script that harvested AWS credentials, ...