Hacker Newsnew | past | comments | ask | show | jobs | submit | fromlogin
The State of Open Source Supply Chain Attacks (stepsecurity.io)
1 point by varunsharma07 20 days ago | past
Codfish/semantic-release-action GitHub Action has been compromised (stepsecurity.io)
4 points by varunsharma07 80 days ago | past
Mastra NPM Supply Chain Attack: 140 Packages Backdoor via easy-day-JS Typosquat (stepsecurity.io)
2 points by shaunpud 88 days ago | past
Pythagora-io/GPT-pilot Compromised – Shai-Hulud Cred Stealer Blocked by ruff (stepsecurity.io)
1 point by yakkomajuri 3 months ago | past
Miasma Worm Hits Microsoft Again (stepsecurity.io)
6 points by matttah 3 months ago | past
Miasma NPM Supply Chain Attack: Self-Spreading Worm via Phantom Gyp (stepsecurity.io)
5 points by gaurang_tandon 3 months ago | past
Megalodon Mass GitHub Actions Secret Exfiltration Across 5500 Public Repos (stepsecurity.io)
4 points by _____k 3 months ago | past
Actions-cool/issues-helper GitHub Action Compromised (stepsecurity.io)
2 points by choult 3 months ago | past
NX compromised: supply chain attack via IDE extension, again (stepsecurity.io)
5 points by Jehuty64 3 months ago | past
Malicious node-IPC versions published to NPM (stepsecurity.io)
2 points by rvz 4 months ago | past
TeamPCP's Mini Shai-Hulud Is Back (stepsecurity.io)
1 point by segmenta 4 months ago | past
Mini Shai-Hulud: Bun Payloads Hit SAP NPM Packages (stepsecurity.io)
9 points by likhith190 4 months ago | past
Axios compromised on NPM – Malicious versions drop remote access trojan (stepsecurity.io)
1934 points by mtud 5 months ago | past | 807 comments
Malicious IoliteLabs VSCode Extensions Target Solidity Developers with Backdoor (stepsecurity.io)
2 points by kurmiashish 5 months ago | past
Trivy Compromised a Second Time – v0.69.4 binaries, setup-trivy, trivy-action (stepsecurity.io)
9 points by dotty- 5 months ago | past | 1 comment
Malicious NPM Packages Found in React Native – 130K+ Monthly Downloads Hit (stepsecurity.io)
4 points by likhith190 6 months ago | past
Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push (stepsecurity.io)
5 points by varunsharma07 6 months ago | past | 1 comment
Xygeni/xygeni-action GitHub Action is compromised – poisoned tag is still live (stepsecurity.io)
2 points by varunsharma07 6 months ago | past
Hackerbot-Claw: An AI-Powered Bot Actively Exploiting GitHub Actions (stepsecurity.io)
2 points by pavel_lishin 6 months ago | past
Hackerbot-Claw: An AI-Powered Bot Actively Exploiting GitHub Actions (stepsecurity.io)
4 points by denysvitali 6 months ago | past
Hackerbot-Claw: An AI-Powered Bot Actively Exploiting GitHub Actions (stepsecurity.io)
2 points by pluc 6 months ago | past
Hackerbot-Claw: AI Bot Exploiting GitHub Actions – Microsoft, Datadog Hit So Far (stepsecurity.io)
27 points by varunsharma07 6 months ago | past | 4 comments
Cline Supply Chain Attack: Cline 2.3.0 Silently Installs OpenClaw (stepsecurity.io)
12 points by varunsharma07 6 months ago | past | 1 comment
Harden Runner Detected the SHA1-Hulud Supply Chain Attack in CNCF's Backstage (stepsecurity.io)
1 point by varunsharma07 9 months ago | past | 1 comment
ctrl/tinycolor and 40+ NPM Packages Compromised (stepsecurity.io)
2 points by tomelders 12 months ago | past | 1 comment
Ctrl/tinycolor and 40 NPM Packages Compromised (stepsecurity.io)
3 points by kurmiashish 12 months ago | past | 1 comment
Popular Nx Build System NPM Package Compromised with Data Stealing Malware (stepsecurity.io)
10 points by varunsharma07 on Aug 27, 2025 | past | 2 comments
Suspicious Tag Change in AWS's GitHub Action: What Happened and Why It Matters (stepsecurity.io)
3 points by varunsharma07 on Aug 14, 2025 | past | 1 comment
Num2words PyPI Package Compromised (stepsecurity.io)
22 points by varunsharma07 on July 28, 2025 | past | 6 comments
AI coding agents in CI/CD pipelines create new attack vectors (stepsecurity.io)
2 points by kurmiashish on July 23, 2025 | past | 1 comment

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: