Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
5 / 5 results
highbug_reportVulnerabilityHijacked npm and Go packages deploy cross-platform stealer via VS Code
Compromised npm and Go packages targeting developers using Microsoft Visual Studio Code on Windows, Linux, and macOS. Attack bypasses npm v12 lifecycle script protections by abusing VS Code task execution.
highbug_reportVulnerabilityMiasma malware compromises npm packages LeoPlatform and RStreams
npm packages LeoPlatform and RStreams compromised by Miasma malware family. Attack extends to GitHub Actions workflows and Go ecosystem. Organizations using these packages or dependent projects are affected.
highbug_reportVulnerabilitynpm v12 disables install scripts by default to block supply chain attacks
npm version 12 and later. All Node.js projects using npm for package management. Breaking change affects packages that legitimately rely on install/postinstall lifecycle hooks.
criticalbug_reportVulnerabilityTrapDoor campaign deploys credential stealers across npm, PyPI, Crates.io
34+ malicious packages (384+ versions) distributed across npm (Node.js), PyPI (Python), and Crates.io (Rust) repositories. Campaign active since May 2026. Affects developers and CI/CD pipelines consuming packages from these ecosystems.
highbug_reportVulnerabilitySupply chain attack compromises 8 Packagist packages with malicious binary
Eight Composer packages on Packagist containing JavaScript components. Malicious code injected into package.json files executes a Linux binary from GitHub Releases. Downstream projects using these packages are affected.