Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
|
from
login
The State of Open Source Supply Chain Attacks
(
stepsecurity.io
)
1 point
by
varunsharma07
20 days ago
|
past
Codfish/semantic-release-action GitHub Action has been compromised
(
stepsecurity.io
)
4 points
by
varunsharma07
80 days ago
|
past
Mastra NPM Supply Chain Attack: 140 Packages Backdoor via easy-day-JS Typosquat
(
stepsecurity.io
)
2 points
by
shaunpud
88 days ago
|
past
Pythagora-io/GPT-pilot Compromised – Shai-Hulud Cred Stealer Blocked by ruff
(
stepsecurity.io
)
1 point
by
yakkomajuri
3 months ago
|
past
Miasma Worm Hits Microsoft Again
(
stepsecurity.io
)
6 points
by
matttah
3 months ago
|
past
Miasma NPM Supply Chain Attack: Self-Spreading Worm via Phantom Gyp
(
stepsecurity.io
)
5 points
by
gaurang_tandon
3 months ago
|
past
Megalodon Mass GitHub Actions Secret Exfiltration Across 5500 Public Repos
(
stepsecurity.io
)
4 points
by
_____k
3 months ago
|
past
Actions-cool/issues-helper GitHub Action Compromised
(
stepsecurity.io
)
2 points
by
choult
3 months ago
|
past
NX compromised: supply chain attack via IDE extension, again
(
stepsecurity.io
)
5 points
by
Jehuty64
3 months ago
|
past
Malicious node-IPC versions published to NPM
(
stepsecurity.io
)
2 points
by
rvz
4 months ago
|
past
TeamPCP's Mini Shai-Hulud Is Back
(
stepsecurity.io
)
1 point
by
segmenta
4 months ago
|
past
Mini Shai-Hulud: Bun Payloads Hit SAP NPM Packages
(
stepsecurity.io
)
9 points
by
likhith190
4 months ago
|
past
Axios compromised on NPM – Malicious versions drop remote access trojan
(
stepsecurity.io
)
1934 points
by
mtud
5 months ago
|
past
|
807 comments
Malicious IoliteLabs VSCode Extensions Target Solidity Developers with Backdoor
(
stepsecurity.io
)
2 points
by
kurmiashish
5 months ago
|
past
Trivy Compromised a Second Time – v0.69.4 binaries, setup-trivy, trivy-action
(
stepsecurity.io
)
9 points
by
dotty-
5 months ago
|
past
|
1 comment
Malicious NPM Packages Found in React Native – 130K+ Monthly Downloads Hit
(
stepsecurity.io
)
4 points
by
likhith190
6 months ago
|
past
Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push
(
stepsecurity.io
)
5 points
by
varunsharma07
6 months ago
|
past
|
1 comment
Xygeni/xygeni-action GitHub Action is compromised – poisoned tag is still live
(
stepsecurity.io
)
2 points
by
varunsharma07
6 months ago
|
past
Hackerbot-Claw: An AI-Powered Bot Actively Exploiting GitHub Actions
(
stepsecurity.io
)
2 points
by
pavel_lishin
6 months ago
|
past
Hackerbot-Claw: An AI-Powered Bot Actively Exploiting GitHub Actions
(
stepsecurity.io
)
4 points
by
denysvitali
6 months ago
|
past
Hackerbot-Claw: An AI-Powered Bot Actively Exploiting GitHub Actions
(
stepsecurity.io
)
2 points
by
pluc
6 months ago
|
past
Hackerbot-Claw: AI Bot Exploiting GitHub Actions – Microsoft, Datadog Hit So Far
(
stepsecurity.io
)
27 points
by
varunsharma07
6 months ago
|
past
|
4 comments
Cline Supply Chain Attack: Cline 2.3.0 Silently Installs OpenClaw
(
stepsecurity.io
)
12 points
by
varunsharma07
6 months ago
|
past
|
1 comment
Harden Runner Detected the SHA1-Hulud Supply Chain Attack in CNCF's Backstage
(
stepsecurity.io
)
1 point
by
varunsharma07
9 months ago
|
past
|
1 comment
ctrl/tinycolor and 40+ NPM Packages Compromised
(
stepsecurity.io
)
2 points
by
tomelders
12 months ago
|
past
|
1 comment
Ctrl/tinycolor and 40 NPM Packages Compromised
(
stepsecurity.io
)
3 points
by
kurmiashish
12 months ago
|
past
|
1 comment
Popular Nx Build System NPM Package Compromised with Data Stealing Malware
(
stepsecurity.io
)
10 points
by
varunsharma07
on Aug 27, 2025
|
past
|
2 comments
Suspicious Tag Change in AWS's GitHub Action: What Happened and Why It Matters
(
stepsecurity.io
)
3 points
by
varunsharma07
on Aug 14, 2025
|
past
|
1 comment
Num2words PyPI Package Compromised
(
stepsecurity.io
)
22 points
by
varunsharma07
on July 28, 2025
|
past
|
6 comments
AI coding agents in CI/CD pipelines create new attack vectors
(
stepsecurity.io
)
2 points
by
kurmiashish
on July 23, 2025
|
past
|
1 comment
More
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: