Tag: GitHub

AI Token Jacking: Stolen API Keys Fueled Nearly $1M Bills

Unit 42 says criminals added stolen AI API keys to gray-market proxy…

Brendan Smith

Leaked n8n API Tokens Exposed 321 Live Instances

GitGuardian found 321 reachable n8n instances still accepting API tokens leaked in…

Brendan Smith

Keyv npm Worm Poisoned 444 Packages: Check Before Rotating Tokens

The Keyv npm worm poisoned hundreds of packages and can react when…

Brendan Smith

Malware Modified Your Git Commits? PolinRider Recovery

Find PolinRider Git rewrite artifacts, preserve commit evidence, clean affected repositories and…

Brendan Smith

XCSSET v40 Turns Xcode Projects Into a macOS Supply-Chain Trap

XCSSET v40 runs through trojanized Xcode projects and adds fileless persistence, browser…

Brendan Smith

Cursor git.exe Flaw: Check Windows Repositories Before Opening

A disclosed Cursor flaw can run a repository-local git.exe on Windows when…

Brendan Smith

Aviator Predictor Malware

Aviator Predictor-style apps can be used as fake crypto and crash-game tools.…

Brendan Smith

Gogs RCE Zero-Day: Check Open Registration

Rapid7 disclosed a critical unpatched Gogs RCE path. Check open registration, repository…

Stephanie Adlam

TrapDoor Hits npm, PyPI and Crates.io With AI Config Poisoning

TrapDoor spreads malicious packages through npm, PyPI and Crates.io, steals developer secrets,…

Stephanie Adlam

Megalodon GitHub Actions Malware

Megalodon injected malicious GitHub Actions workflows into 5,561 repositories. Here is what…

Stephanie Adlam

DenoRAT Malware: ClickFix, DinDoor and NightshadeC2

DenoRAT is a Deno-based RAT and stealer delivered through ClickFix, DinDoor, and…

Stephanie Adlam

npm Staged Publishing: What Maintainers Should Change Now

npm CLI 11.15.0 adds staged publishing and new install-source controls. Here is…

Stephanie Adlam

AI Assistant

Hello! 👋 How can I help you today?