After a 111-day hiatus, Aikido detected a previously-documented Shai-Hulud worm payload in four npm package releases ...
Voters in eastern Nebraska's 1st Congressional District might not see Republican U.S. Rep. Mike Flood and Democrat Chris ...
Five bugs, five root causes so small they were almost insulting.
In the Web app ecosystem alone, the Bun framework just got an AI-fueled Rust makeover, Tailwind CSS version 4 got a new Rust ...
Crypto theft in 2026 is increasingly starting before users even open a wallet. Attackers are compromising software packages ...
Cybercriminals are increasingly hijacking Node.js, the widely used JavaScript runtime, to slip malicious code past security defenses.
Attackers abuse Node.js to execute malicious scripts and deploy payloads in attacks targeting governments, technology ...
Mirage Kitten used fake LinkedIn coding tests to spread NodeRabbit and PollCat, even banning AI tools that could have spotted the malware.
Add iMessage to a Convex AI agent with Photon. See durable webhooks, burst handling, cancellation, deduplication, and ...
Nimbus Manticore uses trojanized coding challenges to deploy NodeRabbit and PollCat RATs across Windows, Linux, and macOS.
The npm package @7nohe/openapi-react-query-codegen, which receives roughly 150,000 weekly downloads, has been compromised by ...
A new Shai-Hulud supply-chain campaign, tracked as Trinitite, has compromised the npm package ...