| | The State of Open Source Supply Chain Attacks (stepsecurity.io) |
| 1 point by varunsharma07 26 days ago | past |
|
| | Codfish/semantic-release-action GitHub Action has been compromised (stepsecurity.io) |
| 4 points by varunsharma07 87 days ago | past |
|
| | Mastra NPM Supply Chain Attack: 140 Packages Backdoor via easy-day-JS Typosquat (stepsecurity.io) |
| 2 points by shaunpud 3 months ago | past |
|
| | Pythagora-io/GPT-pilot Compromised – Shai-Hulud Cred Stealer Blocked by ruff (stepsecurity.io) |
| 1 point by yakkomajuri 3 months ago | past |
|
| | Miasma Worm Hits Microsoft Again (stepsecurity.io) |
| 6 points by matttah 3 months ago | past |
|
| | Miasma NPM Supply Chain Attack: Self-Spreading Worm via Phantom Gyp (stepsecurity.io) |
| 5 points by gaurang_tandon 3 months ago | past |
|
| | Megalodon Mass GitHub Actions Secret Exfiltration Across 5500 Public Repos (stepsecurity.io) |
| 4 points by _____k 3 months ago | past |
|
| | Actions-cool/issues-helper GitHub Action Compromised (stepsecurity.io) |
| 2 points by choult 4 months ago | past |
|
| | NX compromised: supply chain attack via IDE extension, again (stepsecurity.io) |
| 5 points by Jehuty64 4 months ago | past |
|
| | Malicious node-IPC versions published to NPM (stepsecurity.io) |
| 2 points by rvz 4 months ago | past |
|
| | TeamPCP's Mini Shai-Hulud Is Back (stepsecurity.io) |
| 1 point by segmenta 4 months ago | past |
|
| | Mini Shai-Hulud: Bun Payloads Hit SAP NPM Packages (stepsecurity.io) |
| 9 points by likhith190 4 months ago | past |
|
| | Axios compromised on NPM – Malicious versions drop remote access trojan (stepsecurity.io) |
| 1934 points by mtud 5 months ago | past | 807 comments |
|
| | Malicious IoliteLabs VSCode Extensions Target Solidity Developers with Backdoor (stepsecurity.io) |
| 2 points by kurmiashish 5 months ago | past |
|
| | Trivy Compromised a Second Time – v0.69.4 binaries, setup-trivy, trivy-action (stepsecurity.io) |
| 9 points by dotty- 6 months ago | past | 1 comment |
|
| | Malicious NPM Packages Found in React Native – 130K+ Monthly Downloads Hit (stepsecurity.io) |
| 4 points by likhith190 6 months ago | past |
|
| | Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push (stepsecurity.io) |
| 5 points by varunsharma07 6 months ago | past | 1 comment |
|
| | Xygeni/xygeni-action GitHub Action is compromised – poisoned tag is still live (stepsecurity.io) |
| 2 points by varunsharma07 6 months ago | past |
|
| | Hackerbot-Claw: An AI-Powered Bot Actively Exploiting GitHub Actions (stepsecurity.io) |
| 2 points by pavel_lishin 6 months ago | past |
|
| | Hackerbot-Claw: An AI-Powered Bot Actively Exploiting GitHub Actions (stepsecurity.io) |
| 4 points by denysvitali 6 months ago | past |
|
| | Hackerbot-Claw: An AI-Powered Bot Actively Exploiting GitHub Actions (stepsecurity.io) |
| 2 points by pluc 6 months ago | past |
|
| | Hackerbot-Claw: AI Bot Exploiting GitHub Actions – Microsoft, Datadog Hit So Far (stepsecurity.io) |
| 27 points by varunsharma07 6 months ago | past | 4 comments |
|
| | Cline Supply Chain Attack: Cline 2.3.0 Silently Installs OpenClaw (stepsecurity.io) |
| 12 points by varunsharma07 7 months ago | past | 1 comment |
|
| | Harden Runner Detected the SHA1-Hulud Supply Chain Attack in CNCF's Backstage (stepsecurity.io) |
| 1 point by varunsharma07 9 months ago | past | 1 comment |
|
| | ctrl/tinycolor and 40+ NPM Packages Compromised (stepsecurity.io) |
| 2 points by tomelders on Sept 17, 2025 | past | 1 comment |
|
| | Ctrl/tinycolor and 40 NPM Packages Compromised (stepsecurity.io) |
| 3 points by kurmiashish on Sept 16, 2025 | past | 1 comment |
|
| | Popular Nx Build System NPM Package Compromised with Data Stealing Malware (stepsecurity.io) |
| 10 points by varunsharma07 on Aug 27, 2025 | past | 2 comments |
|
| | Suspicious Tag Change in AWS's GitHub Action: What Happened and Why It Matters (stepsecurity.io) |
| 3 points by varunsharma07 on Aug 14, 2025 | past | 1 comment |
|
| | Num2words PyPI Package Compromised (stepsecurity.io) |
| 22 points by varunsharma07 on July 28, 2025 | past | 6 comments |
|
| | AI coding agents in CI/CD pipelines create new attack vectors (stepsecurity.io) |
| 2 points by kurmiashish on July 23, 2025 | past | 1 comment |
|
|
| More |