Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 50 results
highbug_reportVulnerabilitySeven malicious npm packages target Vite ecosystem with blockchain C2 RAT
npm package ecosystem, specifically projects using Vite frontend tooling. Seven malicious packages identified in the ViteVenom campaign. Any JavaScript/Node.js development environments that installed these packages are compromised.
criticalbug_reportVulnerabilityDigiCert breach linked to Chinese APT; code-signing certs stolen
DigiCert certificate authority infrastructure compromised in April 2026. Code-signing certificates stolen by CylindricalCanine (GoldenEyeDog/APT-Q-27 subgroup).
highbug_reportVulnerabilityMalicious npm and PyPI packages impersonate Paysafe payment SDKs
Developers using npm and PyPI repositories who may have installed counterfeit packages impersonating Paysafe, Skrill, and Neteller payment SDKs. Affects development environments and potentially downstream applications integrating these malicious pack…
highbug_reportVulnerabilityNorth Korean actors deploy 108 malicious packages in PolinRider campaign
npm, Packagist (PHP), Go modules, and Google Chrome Web Store. 108 malicious packages and extensions published. Maintainer accounts actively compromised. Campaign linked to North Korean Contagious Interview threat group.
highbug_reportVulnerabilityNorth Korean actors deploy malicious npm packages to steal developer secrets
npm ecosystem: malicious packages "rollup-packages-polyfill-core" and "rollup-runtime-polyfill-core" impersonating legitimate "rollup-plugin-polyfill-node".
highbug_reportVulnerabilityLLM hallucinations exploited for supply chain attacks via phantom domains
Organizations using LLMs for development assistance, code generation, or package recommendations. Developers relying on AI-generated domain/package suggestions without verification.
highbug_reportVulnerabilityTrojanized Pyrogram forks on PyPI target Telegram bot developers
Python developers using PyPI packages for Telegram bot development. Malicious forks of Pyrogram library active since November 2024. Affects developers who may have installed compromised packages instead of legitimate Pyrogram.
highbug_reportVulnerabilityHijacked npm and Go packages deploy cross-platform stealer via VS Code
Compromised npm and Go packages targeting developers using Microsoft Visual Studio Code on Windows, Linux, and macOS. Attack bypasses npm v12 lifecycle script protections by abusing VS Code task execution.
highbug_reportVulnerabilityAgentic coding tools vulnerable to hidden malicious payloads in repos
Agentic coding tools and AI-assisted development platforms that automatically fetch and execute code from GitHub repositories. Specific products not disclosed.
highbug_reportVulnerabilityPolymarket frontend compromised via third-party vendor; $3M stolen
Polymarket platform users. Attack vector: malicious JavaScript injected into frontend via compromised third-party vendor. Approximately $3 million in customer funds stolen. No CVE assigned.
highbug_reportVulnerabilityMiasma malware compromises npm packages LeoPlatform and RStreams
npm packages LeoPlatform and RStreams compromised by Miasma malware family. Attack extends to GitHub Actions workflows and Go ecosystem. Organizations using these packages or dependent projects are affected.
criticalbug_reportVulnerabilityCI/CD flaw "Cordyceps" exposes 300+ GitHub repos to supply-chain takeover
300+ GitHub repositories across major organizations including Microsoft, Google, and Apache. Vulnerability affects GitHub Actions CI/CD workflows. Specific products and versions not disclosed in available data.
highbug_reportVulnerabilityMalicious AI skills in ClawHub marketplace evade scanners, deploy infostealers
ClawHub marketplace users consuming third-party AI skills. Specific affected products: OpenClaw and ClawHub platforms. Scope includes organizations deploying AI agents with marketplace-sourced skills that may contain evasive malware delivering infost…
highbug_reportVulnerabilityGitHub blocks pwn request attacks in actions/checkout starting June 2026
GitHub Actions workflows using actions/checkout with pull_request_target trigger. Organizations using GitHub Actions for CI/CD pipelines are affected. The security update applies to all repositories using the actions/checkout action after June 18, 20…
highbug_reportVulnerabilityLastPass breached via Klue supply chain attack; OAuth tokens stolen
LastPass customers. Attack vector: compromised Klue third-party service leading to OAuth token theft and unauthorized access to LastPass Salesforce environment containing customer data.
highbug_reportVulnerabilityMalicious npm packages deliver Windows RAT to JavaScript developers
Three npm packages (aes-decode-runner-pro, postcss-minify-selector, postcss-minify-selector-parser) published within the past month. Total downloads: 145-615 per package. Affects Windows-based development environments using npm package manager.
highbug_reportVulnerabilityShapedPlugin WordPress Pro plugins backdoored via compromised update channel
Multiple ShapedPlugin Pro WordPress plugins distributed through official licensed update channels. Exact plugin names and affected versions not specified.
highbug_reportVulnerabilityNorth Korean APT compromised 140+ npm packages via Mastra AI framework
Mastra AI framework and over 140 dependent npm packages. Organizations using Mastra AI or downstream dependencies in Node.js/JavaScript applications are affected.
highbug_reportVulnerabilitySalesforce disables Klue integration after OAuth token abuse exposes data
Salesforce customers using the Klue Battlecards app integration. OAuth tokens were abused to access customer data. Integration disabled as of June 11, 2026.
highbug_reportVulnerabilityShapedPlugin WordPress plugins compromised in supply chain attack
Multiple WordPress plugins from ShapedPlugin vendor. Infected releases distributed to paying customers via official update mechanism. Specific plugin names and version numbers not disclosed in provided data.
highbug_reportVulnerabilityPoisoned npm package compromises 140+ projects via postinstall payload
140+ projects using a malicious npm package containing a hidden postinstall script. Affects Node.js/JavaScript development environments consuming npm dependencies. Specific package name not disclosed in summary.
criticalbug_reportVulnerabilitySupply chain attack compromises 144 Mastra npm packages via hijacked account
144 npm packages in the @mastra/* namespace (Mastra AI framework for JavaScript/TypeScript). Attack vector: compromised npm contributor account (ehindero). All downstream projects using affected Mastra packages are potentially impacted.
highbug_reportVulnerabilityMalicious JetBrains IDE plugins steal AI API keys from developers
JetBrains Marketplace users who installed any of the 15+ malicious plugins. Affects developers using JetBrains IDEs (IntelliJ IDEA, PyCharm, WebStorm, etc.) with AI API keys configured. Specific plugin names and versions not provided in summary.
highbug_reportVulnerabilityAwesome Motive CDN breach compromises WordPress plugins in supply-chain attack
WordPress plugins OptinMonster, TrustPulse, and PushEngage distributed via Awesome Motive's CDN. All versions served through the compromised CDN infrastructure are potentially affected.
criticalbug_reportVulnerabilitySupply chain attack hits PushEngage, OptinMonster, TrustPulse plugins
WordPress sites using PushEngage, OptinMonster, and TrustPulse plugins. All versions loading compromised JavaScript files from vendor infrastructure are affected.
criticalbug_reportVulnerabilityArch User Repository supply chain attack: 400+ packages backdoored
Arch Linux users who installed or updated packages from the Arch User Repository (AUR) during the compromise window. Over 400 AUR packages contained malicious build scripts deploying a Rust-based infostealer.
criticalbug_reportVulnerability400+ Arch User Repository packages compromised with rootkit and infostealer
Arch Linux users who installed or updated packages from the Arch User Repository (AUR). Over 400 AUR packages confirmed compromised. Specific package names and versions not yet disclosed.
highbug_reportVulnerabilitynpm v12 disables install scripts by default to block supply chain attacks
npm version 12 and later. All Node.js projects using npm for package management. Breaking change affects packages that legitimately rely on install/postinstall lifecycle hooks.
highbug_reportVulnerabilityMiasma credential-stealing framework source code leaked on GitHub
Open-source software ecosystems and their supply chains. Organizations consuming packages from public repositories (npm, PyPI, RubyGems, etc.) are at increased risk. No specific vendor or product version affected; threat is ecosystem-wide.
highbug_reportVulnerabilityMicrosoft GitHub repos compromised, 73 disabled for distributing malware
73 repositories across Microsoft's official GitHub organizations (Azure, microsoft, Azure-Samples, MicrosoftDocs). Organizations using Microsoft sample code, Azure templates, or CI/CD pipelines referencing these repositories are potentially affected.