A malicious version of the PyTorch Lightning package published on the Python Package Index (PyPI) delivers a ...
ThreatDown’s EDR team discovered a sophisticated, multi-stage attack chain during an active investigation; the first documented case of attackers abusing the Deno runtime as a malware execution ...
Multiple official SAP npm packages were compromised in what is believed to be a TeamPCP supply-chain attack to steal ...
In the first five months of 2026, security researchers have flagged more malicious packages on the npm registry than in all ...