A group of VS Code theme extensions linked to GlassWorm, a malware campaign targeting developers. Their investigation ...
September 27, 2026Today, a development build of an app called "Mikaron Development Build" was installed on Chibi-chan's ...
【プロローグ】 ミカ「教授、次はSQLiteを使うのですよね。Flutterもインストールしておきました」 教授「今回はFlutterを使わない」 ミカ「では、TypeScriptだけでスマートフォンを動かすのですか」 ...
A malicious npm package reached over 2 million weekly downloads by hiding its payload in a routine library function rather than an install script.
An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than ...
An npm worm has returned, infecting four packages and stealing tokens while spreading through developers’ publishing rights.
Documentation files on more than 100 websites are referencing potentially dangerous executable content that gets installed automatically when visited by many AI agents. A few dozen companies, some of ...
A new variant of the Shai-Hulud npm worm has poisoned hundreds of packages while adding propagation techniques that can leave little trace in the corresponding source repositories. In Frank Herbert’s ...
A monthly overview of things you need to know as an architect or aspiring architect. Unlock the full InfoQ experience by logging in! Stay updated with your favorite authors and topics, engage with ...
Malware infected at least 444 npm packages spanning 2,000 versions, threatening software with over two billion monthly installs. Attackers compromised maintainer Jared Wray's account, then used stolen ...
A credential-stealing npm worm that first appeared in keyv@6.0.0 spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4, 2026. SafeDep ...