GlassWorm Escalates: 73 New “Sleeper” Extensions Discovered on Open VSX Marketplace
Aikido Security has identified 73 new GlassWorm "sleeper" extensions on the Open VSX marketplace, marking a dangerous escalation in a supply chain campaign targeting developers through hidden malicious...
Malicious npm Package js-logger-pack Turns Hugging Face Into Malware CDN and Data Exfiltration Backend
JFrog Security researchers have uncovered a malicious npm package, js-logger-pack, that uses Hugging Face as both a malware delivery network and an exfiltration backend for stolen data. The...
Checkmarx KICS Docker Hub Repo Hijacked: Trojanized Images and VS Code Extensions Harvest Developer Secrets
Attackers overwrote official Checkmarx KICS tags on Docker Hub and weaponized its VS Code extensions to deploy a credential stealer that exfiltrates GitHub tokens, AWS keys, SSH keys,...
Vercel Confirms OAuth Supply Chain Breach Linked to Context.ai Compromise; ShinyHunters Claims Responsibility
Vercel has disclosed an internal breach caused by a compromised Context.ai OAuth token harvested via Lumma Stealer. A limited set of customer accounts had non-sensitive environment variables exposed,...
ShinyHunters Breaches Rockstar Games via Supply Chain Attack: 80 Million Records Ransomed, Data Leaked After Deadline
ShinyHunters compromised Rockstar Games through a supply chain attack on third-party analytics provider Anodot, stealing 80 million records from Snowflake data warehouses. After a $200,000 ransom deadline expired...
Fake Ledger Live App on Apple’s Mac App Store Steals $9.5 Million in Crypto from 50+ Victims
A counterfeit Ledger Live app remained live on Apple's Mac App Store for two weeks, tricking users into entering their cryptocurrency wallet seed phrases. At least 50 victims...
ShinyHunters Breaches Rockstar Games via Third-Party Vendor, Threatens to Leak GTA VI Contracts
ShinyHunters has breached Rockstar Games by exploiting authentication tokens from third-party analytics vendor Anodot to access Snowflake data warehouses. The stolen data reportedly includes financial records and confidential...
Stryker Corporation Discloses Material Cybersecurity Incident Disrupting Global Manufacturing Operations
Stryker Corporation has disclosed a material cybersecurity incident that disrupted its global manufacturing, commercial, ordering, and distribution systems in March 2026. The medical device giant filed an amended...