ChainDrop Worm Spreads Through 400+ npm Packages, Raiding Developer and Cloud Credentials
A self-propagating worm dubbed ChainDrop has infected more than 400 npm packages by hijacking trusted publishing accounts, quietly harvesting npm, GitHub, cloud, and SSH credentials from developer machines...
Researchers Find Matching RCE Flaws in Claude Code, Gemini CLI and Codex Coding Agents
Security researcher Elad Meged has uncovered a strikingly similar vulnerability pattern across AI coding agents from Anthropic, Google, and OpenAI, all traceable to how each vendor's surrounding 'harness'...
Fake VS Code Extensions Quietly Siphoned Git and CI Secrets From Developers
Seventy-seven counterfeit Open VSX extensions impersonated legitimate developer tools and quietly phoned home to a single attacker-controlled domain. Nineteen of them went further, harvesting Git repository details and...
How One Poisoned Tracking Script Turned a Major Ad Platform Into a Crypto-Theft Pipeline
Researchers say attackers hijacked a widely deployed JavaScript file from ad-tech company Adform, turning routine website analytics into a silent clipboard hijacker that swaps copied crypto wallet addresses...
Coca-Cola’s Fairlife Brand Halts US Production After Ransomware Hits Manufacturing Systems
Coca-Cola disclosed in an SEC filing that its Fairlife dairy subsidiary suffered a ransomware attack that forced a temporary halt of US production, while Canadian operations continued unaffected....
Shai-Hulud Malware Expands to npm Ecosystem, Stealing Cloud and CI/CD Credentials From Developers
A credential-stealing malware campaign known as Shai-Hulud has expanded to target developers using the Leo/RStreams npm package ecosystem, harvesting GitHub tokens, cloud access keys, CI/CD secrets, and SSH...
Klue Supply Chain Hack Exposes Salesforce Data at Nine Cybersecurity Companies
A supply chain attack on market intelligence platform Klue has compromised Salesforce CRM data across at least nine organizations, including HackerOne, Huntress, and Recorded Future. The Icarus extortion...
Supply Chain Attack Compromises 140+ Mastra npm Packages, Targeting Developer Credentials and Crypto Wallets
A sophisticated supply chain attack has compromised over 141 packages in the Mastra-AI npm ecosystem, including @mastra/core which sees 918,000 weekly downloads. Detected on June 17, 2026, the...