<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>SafeDep’s Blog</title><description>SafeDep continuously scans packages published in npm, PyPI, RubyGems, and more for malicious code, protecting software development teams at different stages of the software supply chain.</description><link>https://safedep.io</link><item><title>AsyncAPI Packages Compromised with Miasma RAT</title><link>https://safedep.io/asyncapi-generator-supply-chain-attack-miasma-rat</link><guid isPermaLink="true">https://safedep.io/asyncapi-generator-supply-chain-attack-miasma-rat</guid><description>Four @asyncapi npm packages were published with obfuscated malware on July 14, 2026 via compromised CI workflows. The payload downloads Miasma RAT, a credential stealer targeting browsers, SSH keys, npm tokens, and crypto wallets. @asyncapi/specs alone has 2.7M weekly downloads.</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Official jscrambler npm Package Compromised Across Multiple Releases</title><link>https://safedep.io/jscrambler-npm-supply-chain-compromise</link><guid isPermaLink="true">https://safedep.io/jscrambler-npm-supply-chain-compromise</guid><description>The official jscrambler npm package (60K monthly downloads) was trojanized starting at 8.14.0 through an npm account or CI compromise. The attacker republished the same Rust infostealer across five releases in three hours, including 19 minutes after a clean remediation release, and pivoted from a preinstall hook to running the dropper from the module code itself to slip past install-script scanners.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate></item><item><title>nodemon-sudo: an npm Backdoor With No Install Script</title><link>https://safedep.io/malicious-nodemon-sudo-tslint-conf-npm-backdoor</link><guid isPermaLink="true">https://safedep.io/malicious-nodemon-sudo-tslint-conf-npm-backdoor</guid><description>nodemon-sudo copies the real nodemon byte for byte, adds nothing malicious to its own code, and injects one extra dependency, tslint-conf, a repackaged pino logger carrying a backdoor. There is no install hook. The payload fires only at runtime, one dependency hop away from the package a developer installed.</description><pubDate>Thu, 09 Jul 2026 10:00:00 GMT</pubDate></item><item><title>@marketfront: 25 npm Packages Reuse a Known Lure</title><link>https://safedep.io/marketfront-dependency-confusion-campaign</link><guid isPermaLink="true">https://safedep.io/marketfront-dependency-confusion-campaign</guid><description>On July 1, 2026, npm user marketfront batch-published 25 packages carrying the same README lure SafeDep has tracked across four earlier accounts (mr.4nd3r50n, pik-libs, t-in-one, emcd-vue): &quot;Internal package — Platform Engineering Team&quot;. The marker is a reusable dependency-confusion template. It stayed constant across every wave while the payload behind it evolved from a process.env beacon into a credential-file harvester with an RC4-hidden C2.</description><pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The Polymarket Trap: A Fake Arbitrage Bot, Ten npm Accounts, and Four Ways to Deliver an Infostealer</title><link>https://safedep.io/defi-infostealer-fake-arbitrage-bot-npm</link><guid isPermaLink="true">https://safedep.io/defi-infostealer-fake-arbitrage-bot-npm</guid><description>A GitHub repository posing as a Polymarket arbitrage bot accumulated 53 forks before anyone flagged the malicious npm package buried in its dependencies. Behind that repo: ten coordinated npm accounts, 30 packages, and four delivery techniques including one that uses npm itself as the payload server. The second-stage credential harvester reads crypto wallets, browser credentials, AWS keys, SSH keys, and password managers.</description><pubDate>Tue, 30 Jun 2026 12:00:00 GMT</pubDate></item><item><title>Miasma Worm Infects Multiple LeoPlatform npm Packages</title><link>https://safedep.io/miasma-worm-hits-leoplatform-20-npm-packages</link><guid isPermaLink="true">https://safedep.io/miasma-worm-hits-leoplatform-20-npm-packages</guid><description>A Miasma worm variant compromised a single maintainer account and used it to publish infected versions of 20 LeoPlatform npm packages within a 3-second window. The worm also pushed weaponized GitHub Actions workflows to at least three repos. The payload is the same Bun-based credential stealer and self-propagating worm documented in our Miasma source code analysis.</description><pubDate>Thu, 25 Jun 2026 10:00:00 GMT</pubDate></item><item><title>The wshu.net npm Campaign Delivers a Multi-Stage Infostealer</title><link>https://safedep.io/wshu-net-npm-credential-stealer-campaign</link><guid isPermaLink="true">https://safedep.io/wshu-net-npm-credential-stealer-campaign</guid><description>One actor seeded 15 npm packages across 13 throwaway scopes in a single morning, each shipping a ~270KB obfuscated downloader behind a postinstall hook. The downloader pulls a Rust infostealer from GitHub Releases that drains crypto wallets, browser credentials, cloud tokens, and SSH keys. Amazon Inspector tracks the same cluster as Operation Friday Harvest.</description><pubDate>Tue, 23 Jun 2026 12:00:00 GMT</pubDate></item><item><title>MYRA: A Full Linux RAT Distributed via npm</title><link>https://safedep.io/malicious-apintergrationpost-npm-myra-rat</link><guid isPermaLink="true">https://safedep.io/malicious-apintergrationpost-npm-myra-rat</guid><description>The npm package apintergrationpost is a red team RAT called MYRA with native C rootkit, triple persistence, fileless execution, live screen streaming, and process masquerade. This analysis documents its full capability set so defenders can detect and respond if it is misused.</description><pubDate>Sun, 21 Jun 2026 18:00:00 GMT</pubDate></item><item><title>@withgoogle/stitch-sdk: Scope Squat Harvests Developer Credentials</title><link>https://safedep.io/withgoogle-stitch-sdk-scope-squat-credential-harvester</link><guid isPermaLink="true">https://safedep.io/withgoogle-stitch-sdk-scope-squat-credential-harvester</guid><description>A malicious npm package squats the @withgoogle scope to impersonate Google Stitch, silently harvesting credentials from Claude Code, git, GitHub CLI, SSH keys, npm, and Docker on install.</description><pubDate>Sat, 20 Jun 2026 12:00:00 GMT</pubDate></item><item><title>Five npm Packages That Hide a Windows Binary Dropper</title><link>https://safedep.io/procwire-npm-windows-dropper-campaign</link><guid isPermaLink="true">https://safedep.io/procwire-npm-windows-dropper-campaign</guid><description>Five npm packages published in a 12-minute burst split a Windows binary dropper across a fake utility toolkit. The loader hides in a preinstall hook, decodes its C2 from a helper package, and fetches a payload from catbox.moe.</description><pubDate>Wed, 17 Jun 2026 16:00:00 GMT</pubDate></item><item><title>Mastra npm Scope Takeover: 143 Packages Drop a RAT</title><link>https://safedep.io/mastra-npm-scope-takeover-supply-chain-attack</link><guid isPermaLink="true">https://safedep.io/mastra-npm-scope-takeover-supply-chain-attack</guid><description>An attacker republished 143 @mastra packages, including @mastra/core, each with one injected dependency: easy-day-js, a dayjs clone whose install hook downloads and runs a remote access trojan.</description><pubDate>Wed, 17 Jun 2026 12:00:00 GMT</pubDate></item><item><title>astro.config.mjs Supply Chain Attack via Blockchain C2</title><link>https://safedep.io/astro-config-blockchain-c2-supply-chain</link><guid isPermaLink="true">https://safedep.io/astro-config-blockchain-c2-supply-chain</guid><description>An obfuscated IIFE hidden in astro.config.mjs fires at every build, beacons an HTTP C2, and pulls staged commands from a Tron-to-BSC blockchain dead drop.</description><pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Miasma Worm: Most Infected GitHub Repos Are Still Live</title><link>https://safedep.io/miasma-worm-still-infected-github-repos</link><guid isPermaLink="true">https://safedep.io/miasma-worm-still-infected-github-repos</guid><description>Eight days after the Miasma worm forged a credential stealer into public GitHub repositories, most are still serving it. A re-scan of the published victim list plus a fresh code-search sweep found 123 repos across 56 accounts still carrying the live 4.3 MB payload on 665 branches. The big names cleaned up. The long tail did not.</description><pubDate>Thu, 11 Jun 2026 10:00:00 GMT</pubDate></item><item><title>Inside the Miasma Software Supply Chain Attack Toolkit</title><link>https://safedep.io/inside-the-miasma-supply-chain-attack-toolkit</link><guid isPermaLink="true">https://safedep.io/inside-the-miasma-supply-chain-attack-toolkit</guid><description>The Miasma worm source code appeared on GitHub through compromised developer accounts. The codebase is a full supply chain attack toolkit with credential exfiltration across AWS, Azure, GCP, and Kubernetes, registry infection for npm, PyPI, and RubyGems via stolen tokens and OIDC trusted publishing, GitHub Actions tag hijacking, AI coding tool config poisoning, and a GitHub commit search based C2 infrastructure.</description><pubDate>Tue, 09 Jun 2026 10:00:00 GMT</pubDate></item><item><title>Config Files That Run Code: Supply Chain Security Blindspot</title><link>https://safedep.io/config-files-that-run-code</link><guid isPermaLink="true">https://safedep.io/config-files-that-run-code</guid><description>Editor and package-manager config files auto-execute commands when a developer opens a folder or installs dependencies. The Miasma worm wired one dropper into seven of them across Claude Code, Gemini, Cursor, VS Code, npm, Composer, and Bundler. Opening a cloned repo is no longer safe.</description><pubDate>Sat, 06 Jun 2026 10:00:00 GMT</pubDate></item><item><title>Miasma Worm Targets AI Coding Agents via GitHub Repos</title><link>https://safedep.io/miasma-worm-ai-coding-agent-config-injection</link><guid isPermaLink="true">https://safedep.io/miasma-worm-ai-coding-agent-config-injection</guid><description>A Miasma worm variant injects a 4.3 MB dropper into GitHub repos across multiple maintainers, wiring it to auto-run through Claude Code, Gemini, Cursor, and VS Code config files. No npm package is published. The trigger is cloning a repo and opening it in an AI coding agent, a shift from the campaign&apos;s earlier node-gyp install-time execution.</description><pubDate>Fri, 05 Jun 2026 10:00:00 GMT</pubDate></item><item><title>Axios Typosquats Deliver the Epsilon Stealer</title><link>https://safedep.io/malicious-faster-axios-npm-epsilon-stealer</link><guid isPermaLink="true">https://safedep.io/malicious-faster-axios-npm-epsilon-stealer</guid><description>Two axios typosquats on npm, turbo-axios and faster-axios, form a campaign delivering Epsilon Stealer through a four-stage chain. The Electron infostealer grabs browser credentials, crypto wallets, Discord tokens, and opens a persistent WebSocket RAT.</description><pubDate>Tue, 02 Jun 2026 12:00:00 GMT</pubDate></item><item><title>Mini Shai-Hulud &quot;Miasma: The Spreading Blight&quot; Hits @redhat-cloud-services: Multiple Packages at Risk</title><link>https://safedep.io/redhat-cloud-services-hit-by-mini-shai-hulud-npm-worm</link><guid isPermaLink="true">https://safedep.io/redhat-cloud-services-hit-by-mini-shai-hulud-npm-worm</guid><description>The attacker compromised the @redhat-cloud-services GitHub Actions OIDC trusted publisher to ship patch-client@4.0.4 with a Mini Shai-Hulud worm. The same publisher controls 32 packages across the scope. The payload harvests cloud, CI, and registry credentials and self-propagates through stolen tokens.</description><pubDate>Mon, 01 Jun 2026 12:37:00 GMT</pubDate></item><item><title>Inside MicrosoftSystem64: A Supply Chain RAT Exfiltrating to HuggingFace</title><link>https://safedep.io/microsoftsystem64-binary-payload-analysis</link><guid isPermaLink="true">https://safedep.io/microsoftsystem64-binary-payload-analysis</guid><description>Deep technical analysis of MicrosoftSystem64, an 81 MB Node.js SEA binary deployed via malicious npm packages. This RAT steals browser credentials, 80+ crypto wallet extensions, Telegram sessions, SSH keys, and screenshots, exfiltrating everything to HuggingFace datasets while maintaining persistence across Windows, macOS, and Linux.</description><pubDate>Thu, 28 May 2026 12:00:00 GMT</pubDate></item><item><title>183 npm Packages Target Cloud and Finance via oob.moika.tech</title><link>https://safedep.io/oob-moika-tech-dependency-confusion-campaign</link><guid isPermaLink="true">https://safedep.io/oob-moika-tech-dependency-confusion-campaign</guid><description>Two npm accounts published 164 malicious packages at version 99.99.99 targeting a cloud platform and a financial institution. Both campaigns share identical payload code, the same C2 endpoint, and the same hardcoded secret — strong evidence of a single actor. Updated June 1 with a fourth account (emcd-vue, 3+ packages) impersonating the EMCD crypto exchange, now with WaCk/JScrambler obfuscation, home-directory persistence, and a FUSION_ second-stage protocol.</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate></item><item><title>141 npm Packages Abuse Registry as Adware Hosting</title><link>https://safedep.io/malicious-npm-terminal3airport-proxy-adware-spam</link><guid isPermaLink="true">https://safedep.io/malicious-npm-terminal3airport-proxy-adware-spam</guid><description>npm account terminal3airport published 141 packages containing a web proxy unblocker disguised as tutoring websites. The packages load popunder ads, external monetization scripts, and Google Analytics tracking, using npm as free static file hosting. An auto-publish shell script automates the spam at scale.</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate></item><item><title>forge-jsxy: 22 Versions of an Actively Developed npm RAT</title><link>https://safedep.io/malicious-forge-jsxy-npm-rat-evolution</link><guid isPermaLink="true">https://safedep.io/malicious-forge-jsxy-npm-rat-evolution</guid><description>forge-jsxy picked up where the taken-down forge-jsx left off, publishing 22 versions over 22 days. Each release added new capabilities: crypto wallet scanning, Chromium extension theft, WebRTC data channels, and relay-driven auto-upgrades. This post traces that evolution version by version.</description><pubDate>Tue, 26 May 2026 18:00:00 GMT</pubDate></item><item><title>Megalodon: Mass GitHub Repo Backdooring via CI Workflows</title><link>https://safedep.io/megalodon-mass-github-repo-backdooring-ci-workflows</link><guid isPermaLink="true">https://safedep.io/megalodon-mass-github-repo-backdooring-ci-workflows</guid><description>Over 5,700 malicious commits were pushed to GitHub repositories on May 18, 2026, replacing GitHub Actions workflows with base64-encoded secret exfiltration payloads. The &quot;megalodon&quot; campaign targeted repos including Tiledesk (9 repos), Black-Iron-Project (8 repos), and hundreds of others. @tiledesk/tiledesk-server versions 2.18.6-2.18.12 on npm carry the backdoor. C2: 216.126.225.129:8443.</description><pubDate>Thu, 21 May 2026 16:06:00 GMT</pubDate></item><item><title>Polymarket npm Packages Steal Crypto Wallet Keys</title><link>https://safedep.io/malicious-polymarket-npm-crypto-wallet-drainer</link><guid isPermaLink="true">https://safedep.io/malicious-polymarket-npm-crypto-wallet-drainer</guid><description>Nine coordinated npm packages target Polymarket traders with a social-engineered postinstall prompt that exfiltrates raw private keys to a Cloudflare Worker. The attacker published all packages within 30 seconds from a throwaway account.</description><pubDate>Thu, 21 May 2026 03:21:00 GMT</pubDate></item><item><title>art-template npm Hijack Delivers iOS Browser Exploit Kit</title><link>https://safedep.io/art-template-npm-supply-chain-compromise</link><guid isPermaLink="true">https://safedep.io/art-template-npm-supply-chain-compromise</guid><description>art-template versions 4.13.3 through 4.13.7 were compromised after the original author was tricked into transferring ownership through an acquisition fraud. The browser bundle injects scripts that previously delivered the Coruna iOS exploit kit and now redirect visitors to Chinese gambling portals.</description><pubDate>Wed, 20 May 2026 19:00:00 GMT</pubDate></item><item><title>Malicious durabletask on PyPI: Multi-Cloud Credential Stealer with Worm Capabilities</title><link>https://safedep.io/malicious-durabletask-pypi-supply-chain-attack</link><guid isPermaLink="true">https://safedep.io/malicious-durabletask-pypi-supply-chain-attack</guid><description>Three compromised versions of the Microsoft durabletask Python SDK (1.4.1, 1.4.2, 1.4.3) were published to PyPI, each downloading a stage-2 payload that steals credentials from AWS, Azure, GCP, Kubernetes, HashiCorp Vault, and password managers, then propagates to other hosts via SSM and kubectl exec.</description><pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate></item><item><title>Mini Shai-Hulud Strikes Again: 317 npm Packages Compromised</title><link>https://safedep.io/mini-shai-hulud-strikes-again-314-npm-packages-compromised</link><guid isPermaLink="true">https://safedep.io/mini-shai-hulud-strikes-again-314-npm-packages-compromised</guid><description>A compromised npm maintainer account published 637 malicious versions across 317 packages including size-sensor, echarts-for-react, timeago.js, and hundreds of @antv scoped packages, affecting 15M+ monthly downloads.</description><pubDate>Tue, 19 May 2026 18:30:00 GMT</pubDate></item><item><title>Compromised node-ipc on npm: Credential Stealer via DNS Exfiltration</title><link>https://safedep.io/malicious-node-ipc-npm-compromise</link><guid isPermaLink="true">https://safedep.io/malicious-node-ipc-npm-compromise</guid><description>Analysis of compromised node-ipc versions 9.1.6, 9.2.3, and 12.0.1 on npm: a maintainer account takeover injects an 80KB obfuscated credential stealer that targets 100+ sensitive files (SSH keys, cloud credentials, environment variables, AI tool configs) and exfiltrates them via DNS tunneling to a C2 server masquerading as Azure infrastructure.</description><pubDate>Thu, 14 May 2026 16:56:04 GMT</pubDate></item><item><title>Malicious npm Packages Backdoor Claude Code Sessions</title><link>https://safedep.io/malicious-npm-packages-claude-code-hooks</link><guid isPermaLink="true">https://safedep.io/malicious-npm-packages-claude-code-hooks</guid><description>Five typosquatting npm packages ship a hidden ELF binary that fires on install and re-runs via Claude Code&apos;s SessionStart hook on every developer session. C2 is 207.90.194.2:443.</description><pubDate>Wed, 13 May 2026 12:00:00 GMT</pubDate></item><item><title>Cache Poisoning Through pull_request_target: The TanStack Incident</title><link>https://safedep.io/tanstack-github-actions-cache-poisoning</link><guid isPermaLink="true">https://safedep.io/tanstack-github-actions-cache-poisoning</guid><description>A GitHub user opened a PR against TanStack Router from a fork, poisoned the shared pnpm cache through a pull_request_target workflow, then force-pushed the branch clean. When the release pipeline restored the poisoned cache, the payload executed. Full attack chain analysis with timeline, IOCs, and remediation.</description><pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate></item><item><title>Mass Supply Chain Attack Hits TanStack, Mistral AI npm and PyPI Packages</title><link>https://safedep.io/mass-npm-supply-chain-attack-tanstack-mistral</link><guid isPermaLink="true">https://safedep.io/mass-npm-supply-chain-attack-tanstack-mistral</guid><description>Over 400 compromised npm package versions and at least 2 PyPI packages published in a coordinated supply chain attack targeting TanStack, Mistral AI, UiPath, OpenSearch, guardrails-ai, and dozens of other packages.</description><pubDate>Tue, 12 May 2026 06:00:00 GMT</pubDate></item><item><title>Endpoint Protection for Developer Machines</title><link>https://safedep.io/endpoint-protection-developer-security</link><guid isPermaLink="true">https://safedep.io/endpoint-protection-developer-security</guid><description>PMG blocks malicious package installs before post-install scripts run. Sync with SafeDep Cloud for fleet-wide visibility across your team&apos;s endpoints and CI runners.</description><pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate></item><item><title>noon-contracts npm Package: DeFi Supply Chain RAT</title><link>https://safedep.io/malicious-noon-contracts-npm-defi-rat</link><guid isPermaLink="true">https://safedep.io/malicious-noon-contracts-npm-defi-rat</guid><description>noon-contracts poses as a Noon Protocol SDK on npm. On install it exfiltrates SSH keys, crypto wallet private keys, AWS credentials (including live STS/S3/SecretsManager calls), Kubernetes secrets, .env files, shell history, and browser wallet paths to C2 at 82.221.101.203:8443. A full eval-based remote shell polls every 45 seconds. Triple persistence via crontab, macOS LaunchAgent, Linux systemd, and shell RC injection.</description><pubDate>Sun, 10 May 2026 17:00:00 GMT</pubDate></item><item><title>martinez-polygon-clipping-tony: Trojanized npm Fork Drops Telegram RAT</title><link>https://safedep.io/malicious-martinez-polygon-clipping-tony-npm-telegram-rat</link><guid isPermaLink="true">https://safedep.io/malicious-martinez-polygon-clipping-tony-npm-telegram-rat</guid><description>martinez-polygon-clipping-tony is a trojanized fork of the legitimate martinez-polygon-clipping npm package. The postinstall hook downloads a PyInstaller-packed Telegram bot from 172.86.73.132 that provides full remote shell, screenshot capture, file upload/download, and self-destruct capabilities on Windows targets.</description><pubDate>Thu, 07 May 2026 18:00:00 GMT</pubDate></item><item><title>node-env-resolve: npm Package Installs a Full RAT</title><link>https://safedep.io/malicious-npm-node-env-resolve-rat</link><guid isPermaLink="true">https://safedep.io/malicious-npm-node-env-resolve-rat</guid><description>node-env-resolve is a malicious npm package that installs a full-featured remote access trojan on developer machines. The RAT streams screens, captures audio, steals browser history, and gives full mouse and keyboard control to a remote operator. The toolkit matches the OtterCookie RAT family linked to North Korea&apos;s Contagious Interview campaign.</description><pubDate>Sun, 03 May 2026 10:00:00 GMT</pubDate></item><item><title>common-tg-service: 502 npm Versions Hijack Telegram</title><link>https://safedep.io/malicious-common-tg-service-npm-telegram-hijacking-framework</link><guid isPermaLink="true">https://safedep.io/malicious-common-tg-service-npm-telegram-hijacking-framework</guid><description>common-tg-service ships 502 npm versions of a Telegram account-takeover framework with hardcoded 2FA credentials, IMAP-based code harvesting, and forced session eviction. Its companion package ams-ssk is the server-side runtime.</description><pubDate>Fri, 01 May 2026 12:00:00 GMT</pubDate></item><item><title>exiouss: Cookie Stealer Bundled in npm Exam Cheat</title><link>https://safedep.io/malicious-exiouss-npm-exam-cheating-tool</link><guid isPermaLink="true">https://safedep.io/malicious-exiouss-npm-exam-cheating-tool</guid><description>exiouss on npm is the latest package from the loltestpad campaign — the same attacker who published the ixpresso-core Windows RAT in April. It bundles a dormant ChatGPT cookie stealer alongside an AI exam cheating tool, targeting students who willingly run it.</description><pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate></item><item><title>PyTorch Lightning Compromised: Shai-Hulud Worm Reaches PyPI</title><link>https://safedep.io/malicious-pytorch-lightning-pypi-compromise</link><guid isPermaLink="true">https://safedep.io/malicious-pytorch-lightning-pypi-compromise</guid><description>PyPI yanked PyTorch Lightning versions 2.6.2 and 2.6.3 after both embedded a two-stage credential-stealing payload. Any import of the library spawns an 11MB obfuscated JavaScript worm identical to the Shai-Hulud payload seen in the April 29 SAP npm campaign.</description><pubDate>Thu, 30 Apr 2026 12:00:00 GMT</pubDate></item><item><title>Mini Shai Hulud and SAP Compromise</title><link>https://safedep.io/mini-shai-hulud-and-sap-compromise</link><guid isPermaLink="true">https://safedep.io/mini-shai-hulud-and-sap-compromise</guid><description>Four SAP npm packages published on April 29, 2026 contain a two-stage credential-stealing payload targeting GitHub tokens, AWS keys, and CI/CD pipelines. The packages share SAP-affiliated maintainers, pointing to a publisher account compromise.</description><pubDate>Wed, 29 Apr 2026 14:00:00 GMT</pubDate></item><item><title>Malicious redeem-onchain-sdk npm Targets Crypto Wallets</title><link>https://safedep.io/redeem-onchain-sdk-polymarket-npm-malware</link><guid isPermaLink="true">https://safedep.io/redeem-onchain-sdk-polymarket-npm-malware</guid><description>redeem-onchain-sdk impersonates a Polymarket helper SDK and exfiltrates SSH keys, AWS credentials, npm tokens, Docker configs, Chrome saved logins, and a month of local git history to an AWS-hosted C2. The payload was shipped dormant for nearly a month, then weaponized with a postinstall hook in four rapid republishes on April 29, 2026.</description><pubDate>Wed, 29 Apr 2026 13:00:00 GMT</pubDate></item><item><title>npm-global-util: Credential Theft and Supply Chain Attack</title><link>https://safedep.io/npm-global-util-malicious-package-analysis</link><guid isPermaLink="true">https://safedep.io/npm-global-util-malicious-package-analysis</guid><description>npm-global-util is a malicious npm package by maintainer raya4321 that exfiltrates credentials and system recon data via a preinstall hook. Part of a 16-package campaign targeting Apple developer CI/CD environments, with a second-stage that attempts to poison apple-app-store-server-library.</description><pubDate>Wed, 29 Apr 2026 10:00:00 GMT</pubDate></item><item><title>Bitwarden CLI Supply Chain Compromise</title><link>https://safedep.io/bitwarden-cli-supply-chain-compromise</link><guid isPermaLink="true">https://safedep.io/bitwarden-cli-supply-chain-compromise</guid><description>A technical writeup of the malicious `@bitwarden/cli@2026.4.0` release linked to the Checkmarx campaign. Covers the poisoned publish path, loader changes, credential theft, GitHub abuse, and responder takeaways.</description><pubDate>Fri, 24 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Malicious Pull Requests: A Threat Model</title><link>https://safedep.io/malicious-pull-requests-threat-model</link><guid isPermaLink="true">https://safedep.io/malicious-pull-requests-threat-model</guid><description>A compact threat model of the malicious pull request as a supply chain attack primitive against GitHub Actions: attacker, goals, assets, controllable surface, and an attack vector taxonomy (V1 through V8).</description><pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate></item><item><title>ixpresso-core: Windows RAT Disguised as a WhatsApp Agent</title><link>https://safedep.io/malicious-ixpresso-core-npm-rat</link><guid isPermaLink="true">https://safedep.io/malicious-ixpresso-core-npm-rat</guid><description>ixpresso-core poses as an AI WhatsApp agent on npm but installs Veltrix, a Windows RAT that steals browser credentials, Discord tokens, and keystrokes via a hardcoded Discord webhook.</description><pubDate>Thu, 16 Apr 2026 00:00:00 GMT</pubDate></item><item><title>PMG dependency cooldown: wait on fresh npm versions</title><link>https://safedep.io/pmg-dependency-cooldown</link><guid isPermaLink="true">https://safedep.io/pmg-dependency-cooldown</guid><description>Package Manager Guard (PMG) blocks malicious installs and now supports dependency cooldown, a configurable window that hides brand-new npm versions during resolution so installs prefer older, already-visible releases.</description><pubDate>Thu, 16 Apr 2026 00:00:00 GMT</pubDate></item><item><title>forge-jsx npm Package: Purpose-Built Multi-Platform RAT</title><link>https://safedep.io/malicious-forge-jsx-npm-rat</link><guid isPermaLink="true">https://safedep.io/malicious-forge-jsx-npm-rat</guid><description>forge-jsx poses as an Autodesk Forge SDK on npm. On install it deploys a system-wide keylogger, recursive .env file scanner, shell history exfiltrator, and a WebSocket-based remote filesystem backdoor to C2 at 204.10.194.247, with persistence via systemd, LaunchAgent, and Task Scheduler.</description><pubDate>Wed, 15 Apr 2026 17:36:35 GMT</pubDate></item><item><title>Malicious npm Package js-logger-pack Ships a Multi-Platform WebSocket Stealer</title><link>https://safedep.io/malicious-js-logger-pack-npm-stealer</link><guid isPermaLink="true">https://safedep.io/malicious-js-logger-pack-npm-stealer</guid><description>js-logger-pack spent three weeks on npm evolving from a probe into a full infostealer and then a binary dropper. Early versions installed an SSH backdoor, hijacked Telegram sessions, drained 27 crypto wallets, and deployed a cross-platform keylogger. After disclosure on April 15, the attacker pivoted to a HuggingFace-hosted binary dropper named MicrosoftSystem64, now at v1.1.26 with 29 total releases.</description><pubDate>Wed, 15 Apr 2026 12:00:00 GMT</pubDate></item><item><title>Malicious dom-utils-lite npm SSH Backdoor via Supabase</title><link>https://safedep.io/malicious-dom-utils-lite-npm-ssh-backdoor</link><guid isPermaLink="true">https://safedep.io/malicious-dom-utils-lite-npm-ssh-backdoor</guid><description>dom-utils-lite and centralogger on npm inject attacker SSH keys into ~/.ssh/authorized_keys and exfiltrate server metadata to Supabase-hosted C2 infrastructure, granting persistent remote access.</description><pubDate>Tue, 14 Apr 2026 12:00:00 GMT</pubDate></item><item><title>Malicious npm Dependency Confusion Campaign Targets Genoma UI and Others</title><link>https://safedep.io/malicious-genoma-ui-npm-dependency-confusion-campaign</link><guid isPermaLink="true">https://safedep.io/malicious-genoma-ui-npm-dependency-confusion-campaign</guid><description>A dependency confusion campaign by npm user victim59 targets at least three organizations through scoped packages @genoma-ui/components, @needl-ai/common, and rrweb-v1. The packages use install hooks to beacon system reconnaissance data to a DigitalOcean C2 server.</description><pubDate>Fri, 10 Apr 2026 07:15:00 GMT</pubDate></item><item><title>big.js Typosquat Campaign Implants SSH Backdoors</title><link>https://safedep.io/malicious-sjs-biginteger-npm-ssh-theft</link><guid isPermaLink="true">https://safedep.io/malicious-sjs-biginteger-npm-ssh-theft</guid><description>Three waves of big.js typosquats (sjs-biginteger, bjs-biginteger, cjs-biginteger) from throwaway npm accounts implant SSH backdoors and exfiltrate credentials to Cloudflare-disguised C2 infrastructure.</description><pubDate>Thu, 09 Apr 2026 12:00:00 GMT</pubDate></item><item><title>@fairwords npm Packages Hit by Credential Worm</title><link>https://safedep.io/malicious-fairwords-npm-credential-worm</link><guid isPermaLink="true">https://safedep.io/malicious-fairwords-npm-credential-worm</guid><description>Three @fairwords npm packages were compromised with a self-propagating worm that harvests credentials, crypto wallets, Chrome passwords, and spreads to other packages using stolen npm tokens.</description><pubDate>Wed, 08 Apr 2026 03:30:00 GMT</pubDate></item><item><title>Malicious @velora-dex/sdk Delivers Go RAT via npm</title><link>https://safedep.io/malicious-velora-dex-sdk-npm-compromised-rat</link><guid isPermaLink="true">https://safedep.io/malicious-velora-dex-sdk-npm-compromised-rat</guid><description>Version 9.4.1 of @velora-dex/sdk, a DeFi SDK with ~2,000 weekly downloads, was compromised to deliver a Go-based remote access trojan (minirat) targeting macOS developers.</description><pubDate>Wed, 08 Apr 2026 01:53:01 GMT</pubDate></item><item><title>Malicious hermes-px on PyPI Steals AI Conversations</title><link>https://safedep.io/malicious-hermes-px-pypi-ai-conversation-stealer</link><guid isPermaLink="true">https://safedep.io/malicious-hermes-px-pypi-ai-conversation-stealer</guid><description>hermes-px on PyPI steals AI conversations via triple-encrypted exfiltration to Supabase, routing through a hijacked university endpoint while injecting a stolen 245KB system prompt.</description><pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate></item><item><title>prt-scan: A 5-Phase GitHub Actions Credential Theft Campaign</title><link>https://safedep.io/prt-scan-github-actions-exfiltration-campaign</link><guid isPermaLink="true">https://safedep.io/prt-scan-github-actions-exfiltration-campaign</guid><description>A throwaway GitHub account submitted 219+ malicious pull requests in a single day, each carrying a 352-line payload that steals CI secrets, injects workflows, bypasses label gates, and scans /proc for credentials. Five payload variants target GitHub Actions, npm, and Python ecosystems. First public disclosure.</description><pubDate>Fri, 03 Apr 2026 18:30:00 GMT</pubDate></item><item><title>Thirty-Six Malicious npm Strapi Packages Deploy Redis RCE, Database Theft, and Persistent C2</title><link>https://safedep.io/malicious-npm-strapi-plugin-events-c2-agent</link><guid isPermaLink="true">https://safedep.io/malicious-npm-strapi-plugin-events-c2-agent</guid><description>A coordinated campaign of thirty-six malicious npm packages published by four sock-puppet accounts (umarbek1233, kekylf12, tikeqemif26, and umar_bektembiev1) targets Strapi CMS deployments with eight distinct payloads evolving from Redis RCE exploitation and Docker container escape through direct PostgreSQL database theft with hardcoded credentials to fileless reverse shells targeting a cryptocurrency payment platform&apos;s Jenkins CI pipeline.
</description><pubDate>Fri, 03 Apr 2026 12:00:00 GMT</pubDate></item><item><title>Compromised npm Package mgc Deploys Multi-Platform RAT</title><link>https://safedep.io/malicious-npm-mgc-compromised-rat</link><guid isPermaLink="true">https://safedep.io/malicious-npm-mgc-compromised-rat</guid><description>The npm package mgc was compromised via account takeover, with four malicious versions published in rapid succession deploying a full Remote Access Trojan targeting macOS, Windows, and Linux.</description><pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Malicious npm Package express-session-js Drops Full RAT Payload</title><link>https://safedep.io/malicious-npm-package-express-session-js</link><guid isPermaLink="true">https://safedep.io/malicious-npm-package-express-session-js</guid><description>A malicious npm package typosquatting express-session fetches and executes a full Remote Access Trojan from a paste service, targeting browser credentials, crypto wallets, SSH keys, and more.</description><pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate></item><item><title>axios Compromised: npm Supply Chain Attack via Dependency Injection</title><link>https://safedep.io/axios-npm-supply-chain-compromise</link><guid isPermaLink="true">https://safedep.io/axios-npm-supply-chain-compromise</guid><description>axios 1.14.1 was published to npm via a compromised maintainer account, injecting a trojanized dependency that executes a multi-platform reverse shell on install. No source code changes in axios itself, just a new entry in package.json.</description><pubDate>Tue, 31 Mar 2026 02:26:00 GMT</pubDate></item><item><title>Compromised telnyx on PyPI: WAV Steganography and Credential Theft</title><link>https://safedep.io/malicious-telnyx-pypi-compromise</link><guid isPermaLink="true">https://safedep.io/malicious-telnyx-pypi-compromise</guid><description>Analysis of malicious telnyx 4.87.1 and 4.87.2 on PyPI — a package with over 1 million monthly downloads: injected code uses WAV audio steganography to deliver payloads that steal credentials and establish persistence. Attributed to TeamPCP.</description><pubDate>Fri, 27 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Malicious litellm 1.82.8: Credential Theft and Persistent Backdoor</title><link>https://safedep.io/malicious-litellm-1-82-8-analysis</link><guid isPermaLink="true">https://safedep.io/malicious-litellm-1-82-8-analysis</guid><description>Analysis of compromised litellm 1.82.8 on PyPI: a .pth file triggers credential theft, AWS/K8s secret exfiltration, and persistent C2 backdoor on install.</description><pubDate>Tue, 24 Mar 2026 00:00:00 GMT</pubDate></item><item><title>sl4x0 Dependency Confusion: 92 Packages Target Fortune 500</title><link>https://safedep.io/sl4x0-dependency-confusion-campaign</link><guid isPermaLink="true">https://safedep.io/sl4x0-dependency-confusion-campaign</guid><description>A sustained dependency confusion campaign by the sl4x0 actor likely targets 20+ organizations including Adobe, Ford, Sony, and Coca-Cola with 92+ malicious npm packages exfiltrating developer data via DNS.</description><pubDate>Tue, 24 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Trivy Supply Chain Compromise: What Happened, What Was Stolen, and How to Respond</title><link>https://safedep.io/trivy-teampcp-supply-chain-compromise</link><guid isPermaLink="true">https://safedep.io/trivy-teampcp-supply-chain-compromise</guid><description>A consolidated technical reference for the TeamPCP supply chain attack against Aqua Security&apos;s Trivy scanner. Covers the full attack chain from AI-assisted initial breach through credential theft, GitHub Actions tag poisoning, a self-propagating npm worm, and Kubernetes escape payloads. Includes IOCs, detection queries, and remediation steps.</description><pubDate>Mon, 23 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Malicious npm Package react-refresh-update Drops Cross-Platform Trojan on Developer Machines</title><link>https://safedep.io/malicious-npm-react-refresh-update</link><guid isPermaLink="true">https://safedep.io/malicious-npm-react-refresh-update</guid><description>A malicious npm package impersonating react-refresh, Meta&apos;s library with 42 million weekly downloads, was detected by SafeDep. The package injects a two-layer obfuscated dropper into runtime.js that silently fetches and executes a platform-specific second-stage payload from malicanbur[.]pro on require(), targeting Windows, Linux, and macOS.
</description><pubDate>Mon, 16 Mar 2026 00:00:00 GMT</pubDate></item><item><title>How to Write Time-Based Security Policies in SafeDep vet</title><link>https://safedep.io/writing-time-based-policies-in-vet-cel</link><guid isPermaLink="true">https://safedep.io/writing-time-based-policies-in-vet-cel</guid><description>Protect against unknown malicious open source packages by enforcing a supply chain cooling-off period using the now() CEL function in SafeDep vet.</description><pubDate>Tue, 10 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Threat Modeling the AI-Native SDLC: Supply Chain Security in the Age of Coding Agents</title><link>https://safedep.io/ai-native-sdlc-supply-chain-threat-model</link><guid isPermaLink="true">https://safedep.io/ai-native-sdlc-supply-chain-threat-model</guid><description>AI agents are rewriting the software development lifecycle. From vibe coding to autonomous CI/CD, every phase now involves an LLM making decisions about your code and dependencies. Here is a threat model for the AI-native SDLC from a supply chain security perspective.</description><pubDate>Mon, 09 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Malicious npm Package pino-sdk-v2 Exfiltrates Secrets to Discord</title><link>https://safedep.io/malicious-npm-package-pino-sdk-v2-env-exfiltration</link><guid isPermaLink="true">https://safedep.io/malicious-npm-package-pino-sdk-v2-env-exfiltration</guid><description>A malicious npm package impersonating the popular pino logger was detected by SafeDep. The package hides obfuscated code inside a legitimate library file to steal environment secrets and send them to a Discord webhook.
</description><pubDate>Fri, 06 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Gryph: Audit Trail for AI Coding Agents</title><link>https://safedep.io/gryph-ai-agent-audit-trail</link><guid isPermaLink="true">https://safedep.io/gryph-ai-agent-audit-trail</guid><description>AI coding agents operate with broad access to your codebase, credentials, and shell. Gryph logs every action they take to a local SQLite database, making agent behavior visible, queryable, and auditable.</description><pubDate>Wed, 04 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Integrate SafeDep MCP in GitHub Agentic Workflow</title><link>https://safedep.io/safedep-mcp-in-github-agentic-workflow</link><guid isPermaLink="true">https://safedep.io/safedep-mcp-in-github-agentic-workflow</guid><description>Learn how to integrate SafeDep MCP with GitHub Agentic Workflows to automatically evaluate the security posture of OSS dependencies in your pull requests using AI.</description><pubDate>Fri, 27 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Shadow AI Discovery: Find Every AI Tool and SDK in Your Stack</title><link>https://safedep.io/shadow-ai-discovery-vet</link><guid isPermaLink="true">https://safedep.io/shadow-ai-discovery-vet</guid><description>AI tools and SDKs are spreading across developer environments faster than security teams can track. vet discovers agents, MCP servers, extensions, and AI SDK usage in code. Open source, local, one CLI.</description><pubDate>Fri, 27 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Malicious npm Packages Target Schedaero via Dependency Confusion</title><link>https://safedep.io/schedaero-dependency-confusion-attack</link><guid isPermaLink="true">https://safedep.io/schedaero-dependency-confusion-attack</guid><description>A detailed analysis of a dependency confusion supply chain attack likely targeting Schedaero, a leading aviation software company. We dissect the payload, the exfiltration mechanism, and the indicators of compromise.</description><pubDate>Wed, 25 Feb 2026 00:00:00 GMT</pubDate></item><item><title>npm SANDWORM_MODE Attack: Step-by-Step Malware Analysis</title><link>https://safedep.io/npm-sandworm-mode-supply-chain-attack</link><guid isPermaLink="true">https://safedep.io/npm-sandworm-mode-supply-chain-attack</guid><description>Step-by-step technical analysis of the SANDWORM_MODE npm supply chain attack. We dissect yarsg and format-defaults malicious packages, decode multi-layer obfuscation, and trace the payload delivery chain.</description><pubDate>Sat, 21 Feb 2026 00:00:00 GMT</pubDate></item><item><title>AI Agent Cline v2.3.0 Compromised: From Prompt Injection to Unauthorized npm Publish</title><link>https://safedep.io/cline-cli-compromised</link><guid isPermaLink="true">https://safedep.io/cline-cli-compromised</guid><description>A compromised npm token was used to publish a tampered version of Cline CLI. A prompt injection vulnerability in Cline&apos;s AI-powered GitHub Actions workflow may have enabled the credential theft.</description><pubDate>Wed, 18 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Why We Built a Hosted MCP Server to Stop Malicious Packages for AI Agents</title><link>https://safedep.io/why-we-built-a-hosted-mcp-server-for-ai-coding-agents</link><guid isPermaLink="true">https://safedep.io/why-we-built-a-hosted-mcp-server-for-ai-coding-agents</guid><description>Exposing an MCP server is trivial. Making it useful for AI agents is not. Here&apos;s what we learned dogfooding our own tool, and why we built a hosted MCP server backed by real-time open source threat intelligence.
</description><pubDate>Mon, 16 Feb 2026 00:00:00 GMT</pubDate></item><item><title>End-to-End test with Nextjs, Playwright and MSW</title><link>https://safedep.io/end-to-end-test-nextjs-msw-playwright</link><guid isPermaLink="true">https://safedep.io/end-to-end-test-nextjs-msw-playwright</guid><description>A practical Next.js 16 App Router E2E setup with Playwright and MSW that keeps server-side fetch deterministic by focusing mocking where it matters, not on server actions.</description><pubDate>Tue, 03 Feb 2026 08:59:02 GMT</pubDate></item><item><title>Agent Skills Threat Model</title><link>https://safedep.io/agent-skills-threat-model</link><guid isPermaLink="true">https://safedep.io/agent-skills-threat-model</guid><description>Discover critical security threats in Agent Skills - Anthropic&apos;s open format for AI agent capabilities. Learn about supply chain attacks, deferred code execution, prompt injection, and multiple attack vectors. Essential reading for developers and security teams implementing AI agents.</description><pubDate>Fri, 23 Jan 2026 10:45:00 GMT</pubDate></item><item><title>The State of MCP Registries</title><link>https://safedep.io/the-state-of-mcp-registries</link><guid isPermaLink="true">https://safedep.io/the-state-of-mcp-registries</guid><description>Explore the architecture of the Model Context Protocol (MCP) and the state of its official registry. Learn how to consume server packages programmatically and discover the underlying challenges of data duplication and security in the current meta-registry ecosystem.</description><pubDate>Sat, 20 Dec 2025 00:00:00 GMT</pubDate></item><item><title>DarkGPT: Malicious Visual Studio Code Extension Targeting Developers</title><link>https://safedep.io/dark-gpt-vscode-malicious-extension</link><guid isPermaLink="true">https://safedep.io/dark-gpt-vscode-malicious-extension</guid><description>Malicious extensions are lurking in the Visual Studio Code marketplace. In this case, we discover and analyze DarkGPT, a Visual Studio Code extension that exploits DLL hijacking to load malicious code through a signed Windows executable.</description><pubDate>Wed, 10 Dec 2025 00:00:00 GMT</pubDate></item><item><title>Unpacking CVE-2025-55182: React Server Components RCE Exploit Deep Dive and SBOM-Driven Identification</title><link>https://safedep.io/react-server-nextjs-critical-vulnerability-find-and-fix-with-sbom</link><guid isPermaLink="true">https://safedep.io/react-server-nextjs-critical-vulnerability-find-and-fix-with-sbom</guid><description>A critical pre-authenticated remote code execution vulnerability (CVE-2025-55182) was disclosed in React Server Components, affecting Next.js applications using the App Router. Learn about the technical details of this prototype pollution vulnerability, how to identify affected applications using SBOM queries.</description><pubDate>Thu, 04 Dec 2025 10:45:00 GMT</pubDate></item><item><title>Shai-Hulud 2.0 npm Supply Chain Attack Technical Analysis</title><link>https://safedep.io/shai-hulud-second-coming-supply-chain-attack</link><guid isPermaLink="true">https://safedep.io/shai-hulud-second-coming-supply-chain-attack</guid><description>Critical npm supply chain attack compromises zapier-sdk, @asyncapi, posthog, and @postman packages with self-replicating malware. Technical analysis reveals credential harvesting, GitHub Actions exploitation, and worm-like propagation affecting 25,000+ repositories. Includes IOCs, detection methods, and remediation steps.</description><pubDate>Mon, 24 Nov 2025 10:45:00 GMT</pubDate></item><item><title>An Opinionated Approach for Frontend Testing for Startups</title><link>https://safedep.io/frontend-testing-guide</link><guid isPermaLink="true">https://safedep.io/frontend-testing-guide</guid><description>How we test our Frontend applications powered by React Query and server components with Vitest.</description><pubDate>Tue, 28 Oct 2025 09:15:30 GMT</pubDate></item><item><title>Curious Case of Embedded Executable in a Newly Introduced Transitive Dependency</title><link>https://safedep.io/curious-case-of-dependency-change-with-embedded-binary-stringish</link><guid isPermaLink="true">https://safedep.io/curious-case-of-dependency-change-with-embedded-binary-stringish</guid><description>A routine dependency upgrade introduced a suspicious transitive dependency with an embedded executable. While manual analysis confirmed it wasn&apos;t malicious, this incident highlights the implicit trust we place in open source code and how attackers exploit the software supply chain through seemingly innocent dependency changes.</description><pubDate>Mon, 27 Oct 2025 00:00:00 GMT</pubDate></item><item><title>Malicious npm Packages Impersonating Hyatt Internal Dependencies</title><link>https://safedep.io/malicious-npm-packages-hyatt-campaign</link><guid isPermaLink="true">https://safedep.io/malicious-npm-packages-hyatt-campaign</guid><description>Three malicious npm packages disguised as Hyatt internal dependencies were discovered using install hooks to execute malicious payloads. All packages share identical attack patterns and infrastructure.</description><pubDate>Thu, 23 Oct 2025 00:00:00 GMT</pubDate></item><item><title>Contributing to SafeDep Open Source Projects during Hacktoberfest 2025</title><link>https://safedep.io/hacktoberfest-safedep-2025</link><guid isPermaLink="true">https://safedep.io/hacktoberfest-safedep-2025</guid><description>Learn how to contribute to SafeDep open source projects during Hacktoberfest 2025 and help secure the open source software supply chain.</description><pubDate>Mon, 06 Oct 2025 00:00:00 GMT</pubDate></item><item><title>Ship Code. Not Malware. SafeDep Launches GitHub App for Malicious Package Protection</title><link>https://safedep.io/ship-code-not-malware-safedep-launches-github-app</link><guid isPermaLink="true">https://safedep.io/ship-code-not-malware-safedep-launches-github-app</guid><description>SafeDep launches a GitHub App for zero-configuration protection against malicious open source packages. Instantly scan pull requests and keep your code repositories safe from supply chain attacks.</description><pubDate>Thu, 25 Sep 2025 08:00:00 GMT</pubDate></item><item><title>Shai-Hulud Supply Chain Attack Incident Response</title><link>https://safedep.io/shai-hulud-supply-chain-attack-response</link><guid isPermaLink="true">https://safedep.io/shai-hulud-supply-chain-attack-response</guid><description>The Shai-Hulud supply chain attack is a major incident targeting
developers through malicious packages in the npm ecosystem. This post
outlines the incident response steps that can be taken to contain and
mitigate the impact of this attack.
</description><pubDate>Mon, 22 Sep 2025 12:00:00 GMT</pubDate></item><item><title>Diff-based SCA with AI is Broken — Real Examples from Pipfile.lock, yarn.lock, and Cargo.lock</title><link>https://safedep.io/pitfalls-of-diff-based-sca-scanners</link><guid isPermaLink="true">https://safedep.io/pitfalls-of-diff-based-sca-scanners</guid><description>Diff-based Software Composition Analysis (SCA) scanners in pull requests are prone to blind spots. By relying only on git diff data,
they miss package context, suffer from nondeterministic rearrangements, and can be trivially bypassed—leaving vulnerabilities undetected.
</description><pubDate>Fri, 19 Sep 2025 00:00:00 GMT</pubDate></item><item><title>npm Supply Chain Attack Exposes Private Repositories, AWS Credentials and More</title><link>https://safedep.io/npm-supply-chain-attack-targeting-maintainers</link><guid isPermaLink="true">https://safedep.io/npm-supply-chain-attack-targeting-maintainers</guid><description>npm supply chain attacks continue. This time targeting @ctrl/tinycolor and multiple other packages with credential stealer malware. In this blog, we will analyze the attack and its impact on the npm ecosystem. We will also look at common attack patterns that are being used to target maintainers.</description><pubDate>Tue, 16 Sep 2025 16:00:00 GMT</pubDate></item><item><title>npm Supply Chain Attack: Multiple Popular Packages Hijacked (1B+ Weekly Downloads)</title><link>https://safedep.io/multiple-npm-packages-compromised-billion-downloads</link><guid isPermaLink="true">https://safedep.io/multiple-npm-packages-compromised-billion-downloads</guid><description>Complete analysis of sophisticated crypto wallet drainer found in 21 npm packages with over one billion weekly downloads. Includes detailed technical breakdown of 76KB malware payload disguised in has-ansi@6.0.1 and multi-stage attack architecture.</description><pubDate>Mon, 08 Sep 2025 16:00:00 GMT</pubDate></item><item><title>nx Build System Compromised Targeting Linux and MacOS developers</title><link>https://safedep.io/nx-build-system-compromise</link><guid isPermaLink="true">https://safedep.io/nx-build-system-compromise</guid><description>The popular npm package `nx` was compromised, targeting Linux and macOS developers. Malicious versions included a postinstall script that stole credentials, exfiltrated sensitive files, and added destructive commands to shell configs, causing system shutdowns and data leaks.</description><pubDate>Wed, 27 Aug 2025 00:00:00 GMT</pubDate></item><item><title>TensorFlow.js Typosquatting Attack: Malicious Package Targeting AI/ML Developers</title><link>https://safedep.io/malicious-npm-package-targeting-tensorflow-users</link><guid isPermaLink="true">https://safedep.io/malicious-npm-package-targeting-tensorflow-users</guid><description>A malicious NPM package targeting TensorFlow users was discovered on npm. The package uses typosquatting to target the popular `tensorflow` package.</description><pubDate>Tue, 12 Aug 2025 00:00:00 GMT</pubDate></item><item><title>Multiple Malicious Python Packages Targeting Bittensor Crypto Developers</title><link>https://safedep.io/malicious-python-packages-target-crypto-developers</link><guid isPermaLink="true">https://safedep.io/malicious-python-packages-target-crypto-developers</guid><description>Multiple malicious Python packages targeting crypto developers and their applications using typosquatting were discovered on PyPI. The packages were used to steal funds by executing a stealthy staking operation.</description><pubDate>Tue, 12 Aug 2025 00:00:00 GMT</pubDate></item><item><title>Security Risks in PEP 723 and uv: Inline Metadata Gone Wrong?</title><link>https://safedep.io/pep-723-inline-metadata-security</link><guid isPermaLink="true">https://safedep.io/pep-723-inline-metadata-security</guid><description>PEP 723 introduces inline metadata for Python scripts, making tools like `uv` more convenient—but also potentially more dangerous. This post explores security pitfalls when dependencies are declared inside code files.
</description><pubDate>Fri, 01 Aug 2025 00:00:00 GMT</pubDate></item><item><title>Secure Vibe Coding with AI Agents</title><link>https://safedep.io/vibe-coding-without-getting-pwned</link><guid isPermaLink="true">https://safedep.io/vibe-coding-without-getting-pwned</guid><description>AI coding agents make development faster but can inadvertently introduce security risks by suggesting unvetted packages. Learn how to use vet MCP server for adding security to your vibe coding adventures.</description><pubDate>Fri, 25 Jul 2025 00:00:00 GMT</pubDate></item><item><title>eslint-config-prettier Compromised: How npm Package with 30 Million Downloads Spread Malware</title><link>https://safedep.io/eslint-config-prettier-major-npm-supply-chain-hack</link><guid isPermaLink="true">https://safedep.io/eslint-config-prettier-major-npm-supply-chain-hack</guid><description>A supply chain attack exploiting eslint-config-prettier and other popular npm packages were discovered with major supply chain impact. In this blog, we will explore the details of the hack and the impact it had on the npm ecosystem.</description><pubDate>Mon, 21 Jul 2025 00:00:00 GMT</pubDate></item><item><title>SBOM Completeness with Direct &amp; Transitive Dependencies</title><link>https://safedep.io/sbom-direct-transitive-deps</link><guid isPermaLink="true">https://safedep.io/sbom-direct-transitive-deps</guid><description>Hidden transitive dependencies create security blind spots. This blog
shows developers and CISOs how SafeDep vet uncovers full Maven dependency
graphs, generating CycloneDX SBOMs and compliance-ready visuals.
</description><pubDate>Sat, 05 Jul 2025 00:00:00 GMT</pubDate></item><item><title>SBOM and the EU Cyber Resilience Act (CRA) – What Software Vendors Need to Know</title><link>https://safedep.io/sbom-and-eu-cra-cyber-resilience-act</link><guid isPermaLink="true">https://safedep.io/sbom-and-eu-cra-cyber-resilience-act</guid><description>The EU Cyber Resilience Act makes SBOMs mandatory for software products sold in Europe starting December 2027, with fines up to €15 million for non-compliance. Here&apos;s what software vendors need to know and how to prepare.</description><pubDate>Fri, 13 Jun 2025 17:58:43 GMT</pubDate></item><item><title>Introducing SafeDep Model Context Protocol (MCP) Server to Secure AI Generated Code</title><link>https://safedep.io/introducing-vet-mcp-server</link><guid isPermaLink="true">https://safedep.io/introducing-vet-mcp-server</guid><description>Introducing SafeDep Model Context Protocol (MCP) Server, a new feature in SafeDep vet to secure AI generated code and protect against slopsquatting attacks, vulnerable and malicious packages.</description><pubDate>Fri, 06 Jun 2025 00:00:00 GMT</pubDate></item><item><title>License Compliance with SBOM</title><link>https://safedep.io/license-compliance-with-sbom</link><guid isPermaLink="true">https://safedep.io/license-compliance-with-sbom</guid><description>Although open-source speeds up development, there are risks associated with licensing. This blog examines the ways in which Software Bills of Materials, or SBOMs, facilitate audits, enforce license compliance, and identify infractions early. Discover how to use tools like Vet to incorporate license checks into your DevSecOps pipeline.</description><pubDate>Thu, 05 Jun 2025 00:00:00 GMT</pubDate></item><item><title>Introducing Container Image Scanning</title><link>https://safedep.io/introducing-container-scanning</link><guid isPermaLink="true">https://safedep.io/introducing-container-scanning</guid><description>Introducing Container Image Scanning, a new feature in vet to identify vulnerabilities and malicious packages in container images.</description><pubDate>Tue, 03 Jun 2025 00:00:00 GMT</pubDate></item><item><title>Software Bill of Materials: Foundation for Trust in Software Supply Chain</title><link>https://safedep.io/software-bill-of-materials-sbom</link><guid isPermaLink="true">https://safedep.io/software-bill-of-materials-sbom</guid><description>Modern software rarely ships as a single, hand-crafted binary. Instead, it is assembled from hundreds, sometimes thousands of third-party components that evolve on their own schedule. Knowing exactly what went into an application is now a basic security expectation, and the Software Bill of Materials (SBOM) is how that knowledge is expressed, stored and shared.</description><pubDate>Sun, 01 Jun 2025 00:00:00 GMT</pubDate></item><item><title>Catching the Silent Threat: How Dynamic Analysis Revealed a Complex npm Attack Chain</title><link>https://safedep.io/digging-into-dynamic-malware-analysis-signals</link><guid isPermaLink="true">https://safedep.io/digging-into-dynamic-malware-analysis-signals</guid><description>Explore how analyzing runtime behaviors using Dynamic Analysis data helps uncover abnormal activities in open source packages. By examining  network connections and unusual binary executions during package installation, we identify potential malicious actors and packages.</description><pubDate>Mon, 19 May 2025 00:00:00 GMT</pubDate></item><item><title>Introducing Package Manager Guard (PMG)</title><link>https://safedep.io/introducing-package-manager-guard</link><guid isPermaLink="true">https://safedep.io/introducing-package-manager-guard</guid><description>Introducing Package Manager Guard (PMG), a new tool to protect developers from malicious packages at the time of installation. Seamless integration with popular package managers like npm, pnpm etc.</description><pubDate>Thu, 15 May 2025 00:00:00 GMT</pubDate></item><item><title>Dynamic Malware Analysis of Open Source Packages at Scale</title><link>https://safedep.io/dynamic-analysis-oss-package-at-scale</link><guid isPermaLink="true">https://safedep.io/dynamic-analysis-oss-package-at-scale</guid><description>Exploring the idea of building a complementary system that can verify and correlate static analysis findings. Thats where dynamic analysis comes in ie. the ability to &quot;run&quot; an open source package in an observed environment and determine its safety status based on real behavior at runtime</description><pubDate>Thu, 01 May 2025 00:00:00 GMT</pubDate></item><item><title>Malicious npm Package Impersonating Popular Express Cookie Parser</title><link>https://safedep.io/malicious-npm-package-express-cookie-parser</link><guid isPermaLink="true">https://safedep.io/malicious-npm-package-express-cookie-parser</guid><description>A malicious npm package impersonating the popular Express cookie parser package was discovered by SafeDep Cloud malicious package scanning service.</description><pubDate>Wed, 23 Apr 2025 00:00:00 GMT</pubDate></item><item><title>Malicious npm Package Impersonating Java SLF4J</title><link>https://safedep.io/malicious-npm-package-impersonating-slf4j</link><guid isPermaLink="true">https://safedep.io/malicious-npm-package-impersonating-slf4j</guid><description>A malicious npm package impersonating the popular Java logging framework SLF4J is discovered by SafeDep Cloud malicious package scanning service.</description><pubDate>Mon, 21 Apr 2025 00:00:00 GMT</pubDate></item><item><title>Announcing DefectDojo Integration</title><link>https://safedep.io/vet-defect-dojo-integration</link><guid isPermaLink="true">https://safedep.io/vet-defect-dojo-integration</guid><description>Introducing DefectDojo Integration allowing vet users to export scan results to DefectDojo. Continue leveraging DefectDojo for your vulnerability management while using vet for identifying vulnerable and malicious open source packages.</description><pubDate>Mon, 14 Apr 2025 00:00:00 GMT</pubDate></item><item><title>Analysis of 5000+ Malicious Open Source Packages</title><link>https://safedep.io/malysis-evaluation-using-datadog-malicious-packages-dataset</link><guid isPermaLink="true">https://safedep.io/malysis-evaluation-using-datadog-malicious-packages-dataset</guid><description>Analysis of malicious open source packages from Datadog&apos;s malicious packages dataset. Each of these packages were found in the wild and confirmed to be malicious. The goal of this analysis is to understand the nature of malicious OSS packages and how they are distributed in the wild.</description><pubDate>Thu, 10 Apr 2025 00:00:00 GMT</pubDate></item><item><title>🚀 Introducing GitLab CI/CD Component</title><link>https://safedep.io/introducing-gitlab-ci-component</link><guid isPermaLink="true">https://safedep.io/introducing-gitlab-ci-component</guid><description>Introducing GitLab CI/CD Component, available in GiLab CI Catalog for seamless integration of vet in GitLab CI. Protect against vulnerable and malicious packages in your GitLab projects.</description><pubDate>Mon, 31 Mar 2025 00:00:00 GMT</pubDate></item><item><title>Agentic Workflows for Malicious Package Analysis</title><link>https://safedep.io/agentic-workflows-for-malicious-package-analysis</link><guid isPermaLink="true">https://safedep.io/agentic-workflows-for-malicious-package-analysis</guid><description>Experiments with agentic workflows for malicious package analysis built using Claude Desktop, Model Context Protocol (MCP) server, static code analysis and SafeDep Cloud API tools.</description><pubDate>Fri, 28 Mar 2025 00:00:00 GMT</pubDate></item><item><title>Typosquatt alert ! Malicious npm Package: nyc-config</title><link>https://safedep.io/nyc-config-malicious-package</link><guid isPermaLink="true">https://safedep.io/nyc-config-malicious-package</guid><description>Possible typosquatting against @istanbuljs/load-nyc-config with ~25M weekly downloads.</description><pubDate>Thu, 13 Mar 2025 00:00:00 GMT</pubDate></item><item><title>Introducing vetpkg.dev - Open Source Component Security Dashboard</title><link>https://safedep.io/introducing-vetpkg-dev</link><guid isPermaLink="true">https://safedep.io/introducing-vetpkg-dev</guid><description>Introducing vetpkg.dev - Built using SafeDep API to provide an easy to use visibility of open source component security information.</description><pubDate>Tue, 18 Feb 2025 00:00:00 GMT</pubDate></item><item><title>Eliminating SCA Noise using Dependency Usage Evidence</title><link>https://safedep.io/vet-code-scanning-dependency-usage-evidence</link><guid isPermaLink="true">https://safedep.io/vet-code-scanning-dependency-usage-evidence</guid><description>SafeDep Code Analysis framework augments vet, our free and open source tool with code context.</description><pubDate>Fri, 07 Feb 2025 00:00:00 GMT</pubDate></item><item><title>What is Next Generation Software Composition Analysis?</title><link>https://safedep.io/what-is-next-gen-sca</link><guid isPermaLink="true">https://safedep.io/what-is-next-gen-sca</guid><description>Software Composition Analysis has been there for a while. But the problems associated with open source vulnerabilities persist. Next-gen SCA is the promised solution. What is it and how does it work?</description><pubDate>Thu, 06 Feb 2025 00:00:00 GMT</pubDate></item><item><title>Malicious npm Packages using Burp Collaborator for Dependency Confusion Attack</title><link>https://safedep.io/burp-collaborator-for-dependency-confusion-attack</link><guid isPermaLink="true">https://safedep.io/burp-collaborator-for-dependency-confusion-attack</guid><description>Multiple npm packages impersonating popular package names were published to the npm registry including by a Snyk researcher apparently targeting internal packages at Cursor AI.</description><pubDate>Thu, 16 Jan 2025 00:00:00 GMT</pubDate></item><item><title>npm - The Playground for Malicious Packages</title><link>https://safedep.io/multiple-npm-malicious-package-impersonating-popular-names</link><guid isPermaLink="true">https://safedep.io/multiple-npm-malicious-package-impersonating-popular-names</guid><description>Multiple npm packages impersonating popular package names are being used to distribute malware. We take a closer look at the campaign.</description><pubDate>Wed, 11 Dec 2024 00:00:00 GMT</pubDate></item><item><title>Malicious Open Source Library Analysis: llm-oracle and its Payload</title><link>https://safedep.io/malicious-oss-package-analysis-llm-oracle</link><guid isPermaLink="true">https://safedep.io/malicious-oss-package-analysis-llm-oracle</guid><description>Malware hidden in open source library packages are real. In this article, we analyse the malicious npm package llm-oracle.</description><pubDate>Mon, 04 Nov 2024 00:00:00 GMT</pubDate></item><item><title>How a Security Team use Policy as Code for Open Source Security</title><link>https://safedep.io/vet-policy-as-code-accel-cyber-security-summit-2024</link><guid isPermaLink="true">https://safedep.io/vet-policy-as-code-accel-cyber-security-summit-2024</guid><description>This is a talk given at Accel Cyber Security Summit 2024 about securing the open source software supply chain using SafeDep vet. This talk highlights a case study of using policy as code for setting up guardrails</description><pubDate>Tue, 22 Oct 2024 00:00:00 GMT</pubDate></item><item><title>SQL Query Interface over SBOM using SafeDep Cloud</title><link>https://safedep.io/safedep-cloud-preview-sql-query-api</link><guid isPermaLink="true">https://safedep.io/safedep-cloud-preview-sql-query-api</guid><description>This is a &apos;#buildinpublic&apos; update for SafeDep Cloud Development. UI often becomes a bottleneck for developer tools causing friction. We want to overcome it by providing an SQL query interface of SBOM and security metadata.</description><pubDate>Fri, 18 Oct 2024 00:00:00 GMT</pubDate></item><item><title>Why Open Source Risks are Larger than SCA Tools</title><link>https://safedep.io/why-oss-risks-larger-than-sca</link><guid isPermaLink="true">https://safedep.io/why-oss-risks-larger-than-sca</guid><description>Open Source Software is critical. However it often comes with inherited risks that are larger than what can be tackled by conventional Software Composition Analysis (SCA) tools.</description><pubDate>Thu, 03 Oct 2024 00:00:00 GMT</pubDate></item><item><title>Sneak Peak into SafeDep Cloud Development and SQL Queries</title><link>https://safedep.io/sneak-peak-into-control-tower-sql-query</link><guid isPermaLink="true">https://safedep.io/sneak-peak-into-control-tower-sql-query</guid><description>Software Bill of Material (SBOM) provides an inventory of all software components. However, they are useful only when a flexible query interface is built on top.</description><pubDate>Mon, 30 Sep 2024 00:00:00 GMT</pubDate></item><item><title>Safe and Secure Consumption of Open Source Libraries</title><link>https://safedep.io/safe-and-secure-oss-consumption</link><guid isPermaLink="true">https://safedep.io/safe-and-secure-oss-consumption</guid><description>Open Source software is the foundation of modern software projects. Any software written today consists of 70-90% of open source code in form of libraries and other components.</description><pubDate>Sun, 15 Sep 2024 00:00:00 GMT</pubDate></item></channel></rss>