#developersecurity
A fake Twilio bug-bounty npm package stole dev credentials under disguise. Audit dependencies carefully. #SecurityNews #npm #SupplyChain #Twilio #Malware #DeveloperSecurity https://thedailytechfeed.com/malicious-npm-package-masquerades-as-twilio-probe-steals-credentials/
September 23, 2026 at 8:36 AM
Miasma malware turns trusted npm packages into persistent backdoors, highlighting urgent supply chain security needs. #Miasma #npm #SupplyChainAttack #CyberSecurity #Malware #DeveloperSecurity thedailytechfeed.com/miasma-malwa...
July 14, 2026 at 3:31 PM
Researchers found Grok Build CLI silently uploads entire Git repos to Google Cloud, including history and secrets, regardless of user settings.

#GrokBuild #xAI #GitPrivacy #AIDataLeak #DeveloperSecurity
Grok Build CLI Silently Uploads Your Entire Git Repo
Researchers analyzing Grok Build CLI, xAI's AI coding assistant, found a potential data privacy issue. A detailed technical writeup describes how the tool may silently upload a user's complete Git repository to cloud servers in the background. That upload reportedly covers more than the current code. It also includes files the tool never read and the complete Git commit history.
securityexpress.info
July 13, 2026 at 2:19 AM
Shai-Hulud Supply Chain Attack Trojanizes 19 PyPI Packages to Steal Developer Secrets

https://blindthoughts.com/shai-hulud-pypi-supply-chain-attack-19-packages

#supplychainattack #pypi #python #malware #developersecurity
June 9, 2026 at 6:17 AM
The result? Your Slack history, API keys, and private files are laid bare—all without you ever clicking "Allow."
Read the full Alert : www.synergyit.com/openclaw-vul...

#AI #OpenClaw #InfoSec #AppSec #SynergyITUSA #DeveloperSecurity #CyberAlert #OpenSource #SecurityUpdate #2026Tech
March 3, 2026 at 10:01 PM
February 26, 2026 at 8:00 PM
July 21, 2026 at 6:17 AM
July 23, 2026 at 5:17 AM
VS Code Zero-Day Exposes GitHub Tokens in One Click — Exploit Code Is Public

https://blindthoughts.com/vs-code-zero-day-github-token-theft

#zeroday #vscode #github #developersecurity #credentialtheft
June 3, 2026 at 7:16 AM
July 14, 2026 at 10:16 AM
Channel9 What's your worst security related coding mistake? #CyberSecurity #CodingMistakes #DeveloperSecurity
- YouTube
Enjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.
www.youtube.com
September 19, 2025 at 11:37 AM
🆕 research on #genAI challenges for modern #appsec. as they need to support developer adoption of #AI, genAI and #chatbots
This is available for @esg_global clients but ping me to learn more
#cloudnativesecurity #applicationsecurity #developersecurity #devsecops
www.techtarget.com/esg-global/r...
Challenges Leveraging Generative AI for Modern Application Security - Enterprise Strategy Group
Organizations are looking to adopt generative AI (GenAI) to enable employees, especially software developers, to increase productivity and gain a competitive advantage.
www.techtarget.com
December 18, 2024 at 1:37 AM
We took down 6 more malicious #VSCode packages that seem to be an evolved brandjacking attack similar the attack on Prettier we previously took down.

List of extensions and additional info: buff.ly/wxviY9d

#SupplyChainSecurity #DeveloperSecurity #ExtensionSecurity #VisualStudioCode
Taking Down More Malicious VSCode Extensions in the 'Prettier' Campaign - Checkmarx
As adversaries improve their tactics for getting malicious content into the Visual Studio Code Marketplace and Open VSX, Checkmarx Zero continues to defend the community. Here's the latest…
checkmarx.com
December 5, 2025 at 4:04 PM
Fake interviews on LinkedIn are now malware drop points: NodeRabbit & PollCat infiltrate dev machines via staged code tests. #Cybersecurity #RAT #NodeRabbit #PollCat #CyberAttack #DeveloperSecurity thedailytechfeed.com/fake-linkedi...
September 9, 2026 at 4:05 PM
ChainDrop worm infects 400+ npm packages, stealing developer credentials like GitHub tokens and cloud keys. #ChainDrop #npm #CyberSecurity #SupplyChainAttack #DeveloperSecurity #GitHub https://thedailytechfeed.com/chaindrop-worm-infects-400-npm-packages-stealing-developer-credentials/
August 7, 2026 at 11:34 AM
Joyfill npm packages compromised with worm-like RAT, posing significant risks to developers. #CyberSecurity #SupplyChainAttack #npm #Joyfill #RAT #DeveloperSecurity thedailytechfeed.com/hijacked-joy...
July 29, 2026 at 3:04 PM
Supply chain attack on AsyncAPI's npm packages exposes developer credentials, urging enhanced security measures. #CyberSecurity #SupplyChainAttack #AsyncAPI #npm #DeveloperSecurity #CredentialTheft thedailytechfeed.com/asyncapi-sup...
July 29, 2026 at 11:31 AM
July 22, 2026 at 4:17 AM
July 20, 2026 at 6:16 AM
SleeperGem attack uses malicious RubyGems to compromise developer machines with persistent backdoors. #CyberSecurity #RubyGems #SupplyChainAttack #Malware #DeveloperSecurity #SleeperGem thedailytechfeed.com/sleepergem-a...
July 20, 2026 at 5:48 AM
Attackers exploit dormant GitHub accounts to map corporate organizations, posing security risks. #GitHubSecurity #CyberSecurity #SupplyChainSecurity #APIThreats #DeveloperSecurity thedailytechfeed.com/dormant-gith...
July 9, 2026 at 7:06 PM
Full Article: www.technadu.com/open-vsx-reg...

Are your teams auditing IDE extensions and registries regularly?
Comment with your mitigation strategies 👇
#CyberSecurity #SupplyChainSecurity #OpenVSX #GlassWorm #MalwareAnalysis #DeveloperSecurity
Open VSX Registry Deploys GlassWorm Malware via Four Malicious Extension Versions
A compromised developer account on Open VSX distributed GlassWorm malware that targeted macOS systems to steal sensitive data.
www.technadu.com
February 2, 2026 at 11:39 AM
PyTorch Lightning and Intercom Client Users Exposed to Credential Stealing Campaign #CloudCredentialExposure #CredentialTheft #DeveloperSecurity
PyTorch Lightning and Intercom Client Users Exposed to Credential Stealing Campaign
  Python's software supply chain has been compromised, which targeted the popular PyPI package Lightning and exposed downstream machine learning environments to covert credential theft through a sophisticated software supply chain compromise.  In conjunction with Aikido Security, OX Security, Socket, and StepSecurity researchers, versions 2.6.2 and 2.6.3, both published on April 30, 2026, have been modified maliciously as part of a broader intrusion related to the "Mini Shai-Hulud" campaign.  A day earlier, the attack emerged through compromised SAP-related npm packages, underlining an ongoing trend of coordinated cross-ecosystem supply chain threats targeting high-value development environments. As a result of this compromise, organizations that utilize PyTorch Lightning, an open-source abstraction layer over PyTorch with over 31,000 stars on Github, face significant risk.  In addition to being frequently embedded in dependency trees facilitating image classification, fine-tuning of large language models, diffusion workloads, and forecasting, Lightning's ubiquity increased the scope of the attack.  A standard pip install lightning command was sufficient for the activation of the malicious chain exploitation did not require a sophisticated trigger. Upon installation of the compromised package, a hidden _runtime directory containing obfuscated JavaScript was created and executed automatically upon module import. This behavior was embedded within the package's initialization logic, ensuring that no additional user interaction was required to execute the script.  Upon receiving the payload, a Python script (start.py) downloaded the Bun JavaScript runtime from external sources, followed by an 11 MB obfuscated file (router_runtime.js) which carried out the attack sequence in stages. An execution model utilizing JavaScript within a Python package utilizing cross-language JavaScript marks a significant evolution in attacker tradecraft. This complicates detection mechanisms focusing on single-language threats. The malware's primary objective was credential harvesting. Analysis indicates that the malware targeted GitHub tokens, cloud service credentials spanning Amazon Web Services (AWS), Google Cloud Platform (GCP), and Azure, SSH keys, NPM tokens, Kubernetes configurations, Docker credentials, and environment variables systematically. Moreover, it was also capable of accessing cryptocurrency wallets and developer secrets stored within local and continuous integration/continuous delivery environments.  By exploiting compromised credentials, stolen data was exfiltrated, often by automating commits to attacker-controlled GitHub repositories, which effectively concealed malicious activity within legitimate developer workflows, effectively masking malicious activity. There were distinctive markers that linked the campaign to the "Shai-Hulud" identity.  Infected environments were observed creating public repositories with unusual naming conventions, including EveryBoiWeBuildIsaWormBoi and descriptions such as "A Mini Shai-Hulud has appeared." Attackers seem to be able to track compromised systems using these artifacts both as infection indicators and as signalling mechanisms.  An effort has been made to link the activity to a financial motivated threat group referred to as TeamPCP, who has consistently demonstrated a focus on credential-rich development environments. According to OX Security, approximately 8.3 million downloads are likely to have been exposed as a result of the incident.  As a result of the attack, Intercom-Client was compromised on the same day, further demonstrating the coordinated nature of the campaign. These incidents are the culmination of a series of supply chain breaches affecting npm, PyPI, and Docker Hub occurring between April 21 and 23 that suggest that a deliberate and sustained effort was made to infiltrate widely trusted software distribution channels between April 21 and 23. The router_runtime.js payload was further examined in order to uncover extensive obfuscation and a clear focus on credential access and repository manipulation. Approximately 700 references were found to process and environment variables, over 460 references were identified to authentication tokens, and approximately 330 references were found to code repositories.  Shai-Hulud operations are closely related to these patterns, which emphasize code reuse and iterative refinement of attack techniques. Furthermore, the payload was also capable of poisoning GitHub repositories and propagating through npm packages, raising concerns about secondary infection vectors beyond data exfiltration.  The Lightning-AI GitHub repository became aware of the compromise when a user reported suspicious behavior under issue #21689 titled “Possible supply chain attack on version 2.6.3.” The report described a hidden execution chain that involved downloading the Bun runtime and executing a large obfuscated payload during module import. Despite this, the issue was later closed without clarification, thereby creating uncertainty concerning the project's initial response to the matter.  Following Socket's disclosure in the Lightning-AI/pytorch-lightning repository, an even more unusual outcome occurred. In a matter of seconds, an account identified as pl-ghost closed the issue warning about compromised versions, and then posted a meme entitled "SILENCE DEVELOPER." This behavior has raised immediate concerns about potential account compromise since it was seen as anomalous.  It was discovered that additional suspicious activity was related to the same account, including six rapid branch creations and deletions across multiple repositories within approximately 70 minutes, which were associated with this account. Several of these branches followed random 10-character lowercase naming conventions, which is consistent with the behavior of the Shai-Hulud worm, which probes for write access.  As well as the branch impersonating Dependabot, another contained inconsistencies such as a misspelled identifier and incorrect naming structure, and all branches were deleted within seconds of being created, and none of them triggered workflows, indicating that automated probing was not being used in development. This combined evidence strongly suggests that the maintainer account may have been compromised, possibly using the same stolen credentials that enabled the malicious package publication on PyPI to be published.  Upon learning of the incident, Python Package Index administrators quarantined Lightning versions that may have been affected. According to the maintainers, an investigation is underway in order to determine the cause, as the compromised releases introduced functionality that was consistent with credential harvesting methods.  In the meantime, it is highly recommended that developers remove versions 2.6.2 and 2.6.3 from their environments, downgrade to version 2.6.1, and rotate any potentially exposed credentials across multiple cloud and development platforms, including API keys, tokens, and access credentials. Besides Python, the campaign is evolving beyond Python. Researchers have confirmed that version 7.0.4 of the intercom-client package within the Node ecosystem has also been compromised, using a preinstall hook to execute credentials-stealing malware. Packagist also has been affected by the attack, where the intercom/intercom-php package (version 5.0.2) has been altered to include a Composer plugin that downloads the Bun runtime using a shell script (setup-intercom.sh) and executes the same obfuscated payload during installation and updates.  As a result of encryption and exfiltration of stolen data to a remote server endpoint, the campaign's adaptability across ecosystems was further demonstrated. It has been determined that the GitHub account "nhur" has likely been compromised, and that the malicious intercom-client package was published through an automated Continuous Integration workflow triggered by a now-deleted branch of GitHub. It appears that technical overlap exists among the npm, PyPI, and PHP ecosystems, with similarities in exfiltration techniques based on GitHub, credential targeting patterns, and payload structures. Furthermore, researchers have found similarities between these attacks and previous ones affecting organizations such as Checkmarx, Bitwarden, Telnyx, LiteLLM, and Aqua Security's Trivy, which supports the hypothesis that a single threat actor is responsible.  Upon suspension from mainstream platforms, TeamPCP reportedly launched an onion-based platform on the dark web to expand its presence. Additionally, the actors have publicly referenced their ties with other cybercriminal groups, including LAPSUS$, while marketing their own tooling infrastructure.  The developments suggest that the threat landscape is becoming increasingly organized and persistent, with supply chain attacks not just isolated incidents but a broader strategy for infiltrating and monetizing developer ecosystems. Lightning and Intercom compromises remain a stark reminder of the fragility of modern software supply chains as investigations continue.  In light of the increasingly capable of pivoting across ecosystems and exploiting trusted distribution channels by attackers, organizations operating in cloud-native environments and AI-based environments have become increasingly reliant on robust dependency auditing, real-time monitoring, and rapid incident response.  The incident highlights a critical juncture in software supply chain security, at which trusted ecosystems are increasingly being weaponised through stealthy, cross-language attack chains that are emerging from across the globe. The coordinated compromises of PyPI, npm, and Packagist packages, together with evidence of maintainer account abuse and automated propagation techniques, demonstrate a high level of operational maturity that challenges traditional methods of detection and response.  It is now necessary to take proactive measures to guard against threats such as TeamPCP, who have demonstrated their capability to infiltrate developer workflows on a large scale. These include rigorous dependency auditing, tighter access controls, and continuous monitoring of build environments.  It is imperative to safeguard the integrity of open-source components in order to maintain confidence in modern software development in the present threat landscape.
dlvr.it
May 2, 2026 at 6:15 AM
March 25, 2026 at 4:01 PM