The malicious version of Cline's npm package — 2.3.0 — was downloaded more than 4,000 times before it was removed.
While the AI itself wasn’t weaponized, the technique raises concerns about AI agents with broad system access.
Researchers warn malicious packages can harvest secrets, weaponize CI systems, and spread across projects while carrying a dormant wipe mechanism.
Orca has discovered a supply chain attack that abuses GitHub Issue to take over Copilot when launching a Codespace from that ...
The module targets Claude Code, Claude Desktop, Cursor, Microsoft Visual Studio Code (VS Code) Continue, and Windsurf. It also harvests API keys for nine large language models (LLM) providers: ...
Zero-day exploits, AI-driven Android malware, firmware backdoors, password manager trust gaps, rising DDoS define this week’s critical cyber threats.
A developer-targeting campaign leveraged malicious Next.js repositories to trigger a covert RCE-to-C2 chain through standard ...
Memphis Light, Gas, and Water identified the cause of the water main break on Sunday, as work downtown continues through the weekend. According to MLGW, a "vintage pipe from the early 1900s" was the ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results