Tag: open-source
Attack reports, vulnerabilities, indicators and intrusion sets linked to open-source.
Attack reports (18)
- Copycat hits another npm package · Published 19/05/2026 00:26 · Modified 19/05/2026 17:59
- AI Infrastructure Supply Chain Poisoning Alert · Published 27/03/2026 19:59 · Modified 27/03/2026 19:31
- An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft, DataDog, and CNCF … · Published 03/03/2026 15:48 · Modified 03/03/2026 16:44
- The Curious Case of the Triton Malware Fork · Published 19/02/2026 15:26 · Modified 19/02/2026 18:13
- Bootstrap script exposes PyPI to domain takeover attacks · Published 03/12/2025 20:19 · Modified 21/12/2025 18:24
- Self-replicating Shai-hulud worm spreads token stealing malware on npm · Published 16/09/2025 21:37 · Modified 17/09/2025 11:56
- Yurei the New Ransomware Group on the Scene · Published 12/09/2025 15:33 · Modified 15/09/2025 19:04
- AdaptixC2: A New Open-Source Framework Leveraged in Real-World Attacks · Published 10/09/2025 16:37 · Modified 10/09/2025 20:11
- Loophole allows threat actors to claim VS Code extension names · Published 29/08/2025 01:02 · Modified 29/08/2025 09:17
- GhostContainer backdoor for Exchange servers · Published 17/07/2025 14:59 · Modified 17/07/2025 19:51
- The Solidity Language open-source package was used in a $500,000 crypto heist · Published 16/07/2025 16:10 · Modified 16/07/2025 19:45
- Threat actor Banana Squad exploits GitHub repos in new campaign · Published 20/06/2025 19:26 · Modified 23/06/2025 23:46