Security researchers have uncovered malicious npm packages linked to North Korea that impersonate Rollup polyfill tools to deliver remote access malware and steal developer credentials and sensitive data.
Adversa AI has disclosed GuardFall, a shell injection bypass affecting 10 of 11 tested open source AI coding agents, exposing systems to command execution and credential theft risks.
A new supply chain attack called Miasma has compromised Red Hat npm packages to steal credentials, target CI/CD environments, and deploy a self propagating malware campaign affecting developers and cloud systems.
Security researchers report malicious Docker images and VS Code extensions tied to Checkmarx supply chain compromise, exposing developer credentials, cloud tokens, and CI/CD secrets through multi-stage malware and npm propagation.
Researchers disclose critical vulnerabilities in four popular Microsoft Visual Studio Code extensions that could enable file theft and remote code execution across developer environments.