Back to Feed

Tag

Open Source

OSS vulnerabilities, package security, dependency risks

50 items tagged #open-source

Articles

13-year-old bug in ActiveMQ lets hackers remotely execute commands

13-year-old RCE vulnerability in Apache ActiveMQ Classic discovered via AI analysis.

Data Leakage Vulnerability Patched in OpenSSL

Seven vulnerabilities patched in OpenSSL, including moderate-severity data leakage flaw.

RCE Bug Lurked in Apache ActiveMQ Classic for 13 Years

13-year-old RCE vulnerability in Apache ActiveMQ Classic can be chained with authentication bypass flaw.

Python Supply-Chain Compromise - Schneier on Security

Malicious .pth file discovered in litellm v1.82.8 PyPI package executes on Python startup.

Tech giants launch AI-powered ‘Project Glasswing’ to identify critical software vulnerabilities

Tech giants launch Project Glasswing, an AI initiative to identify critical software vulnerabilities before malicious

Max severity Flowise RCE vulnerability now exploited in attacks

Max-severity RCE vulnerability CVE-2025-59528 in Flowise AI platform actively exploited.

Critical Flowise Vulnerability in Attacker Crosshairs

Critical Flowise RCE vulnerability CVE-2025-59528 exploited in the wild, affects 12,000+ instances.

Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances Exposed

Flowise AI platform CVE-2025-59528 (CVSS 10.0) RCE under active exploitation; 12,000+ instances exposed.

AI-Assisted Supply Chain Attack Targets GitHub

AI-assisted supply chain attack targets GitHub users via automated misconfiguration exploitation.

Axios Attack Shows Social Complex Engineering Is Industrialized

Axios NPM package targeted in scaled social engineering attack on open source maintainers.

How LiteLLM Turned Developer Machines Into Credential Vaults for Attackers

TeamPCP compromised LiteLLM PyPI packages to inject infostealer malware targeting developer credentials.

Guardarian Users Targeted With Malicious Strapi NPM Packages

36 malicious NPM packages posing as Strapi plugins targeted Guardarian users.

North Korean Hackers Target High-Profile Node.js Maintainers

North Korean UNC1069 targets Node.js maintainers with social engineering to compromise NPM packages.

Axios npm hack used fake Teams error fix to hijack maintainer account

North Korean UNC1069 compromised Axios npm maintainer via social engineering to publish malicious package versions.

UNC1069 Targets Node.js Maintainers via Fake LinkedIn, Slack Profiles

UNC1069 targets Node.js maintainers via fake LinkedIn/Slack profiles to compromise npm packages.

AI Firm Mercor Confirms Breach as Hackers Claim 4TB of Stolen Data

AI firm Mercor confirms breach linked to LiteLLM supply chain attack; Lapsus$ claims 4TB stolen data.

UNC1069 Social Engineering of Axios Maintainer Led to npm Supply Chain Attack

UNC1069 social engineered Axios npm maintainer to publish trojanized package versions.

‼️ CVE-2026-5027: Langflow Path Traversal to Remote Code Execution PoC CVSS: 8.8 GitHub: https:...

CVE-2026-5027: Langflow path traversal vulnerability enables remote code execution.

Claude Code leak used to push infostealer malware on GitHub

Threat actors exploit Claude Code source leak via fake GitHub repos to distribute Vidar infostealer malware.

One of our researchers built an AI powered supply chain monitoring tool on a Friday afternoon. T...

Elastic Security Labs open-sources AI-powered supply chain monitoring tool that detected Axios npm compromise.

🚨 Breaking: On March 31, 2026, a threat actor used stolen maintainer credentials to compromise t...

Threat actor compromises Axios npm package with stolen credentials, deploys ZshBucket malware.

There is a FUD Linux sample here: http://103.79.79[.]21:8899/dl/linux_amd64 As usual, @smica83 wo...

FUD Linux malware sample discovered and shared for analysis.

Mitigating the Axios npm supply chain compromise

Axios npm packages compromised by North Korean Sapphire Sleet with second-stage RAT deployment.

Vulnerability & Patch Roundup — March 2026

WordPress ecosystem plugins patched for multiple medium/critical vulnerabilities in March 2026.

Good work by our teammate @_swachchhanda_ on publishing a dedicated Sigma rule set for the Axios...

Sigma detection rules published for Axios npm package compromise incident.

Claude Code Source Leaked via npm Packaging Error, Anthropic Confirms

Anthropic's Claude Code source leaked via npm packaging error, triggering typosquat attacks.

Claude Code source code accidentally leaked in NPM package

Anthropic accidentally leaked Claude Code source code via NPM package due to misconfigured build artifact.

Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security Infrastructure

TeamPCP compromises Trivy, KICS, LiteLLM, and Telnyx SDK in multi-stage supply chain attack.

Axios NPM Package Compromised in Precision Attack

Axios NPM package compromised in precision attack, possibly by North Korean actors.

3-ways-how-to-get-free-gems-in-clash-of-clans834 - npm Packa...

Malicious npm package 3-ways-how-to-get-free-gems-in-clash-of-clans834 removed after supply chain attack detected.

We have discovered a massive supply chain compromise in the Axios npm package. A backdoored main...

Axios npm package compromised via backdoored maintainer account delivering cross-platform RAT.

Key takeaways: - A compromised npm maintainer account was used to publish two malicious versions...

Compromised npm maintainer published malicious Axios versions with multi-platform implants.

Attack on axios software developer tool threatens widespread compromises

Hacker compromised axios npm account and published malware-laden versions with 600K downloads.

ElasticSecurityLabs detects the Axios npm supply chain attack across Linux, Windows & macOS....

Elastic Security Labs detects Axios npm supply chain attack affecting multiple platforms.

Hackers compromise Axios npm package to drop cross-platform malware

Axios npm package hijacked to deliver cross-platform RATs to 100M+ weekly users.

Hackers Poison Axios npm Package with 100 Million Weekly Downloads

Axios npm package compromised in supply chain attack, exposing 100M weekly downloads to RAT malware.

CrewAI Vulnerabilities Expose Devices to Hacking

Four chained vulnerabilities in CrewAI allow sandbox escape and arbitrary code execution via prompt injection.

🚨 Supply chain issue in axios on npm. The malicious versions 1.14.1 and 0.30.4 pulled in plain-...

Malicious axios npm versions 1.14.1 and 0.30.4 inject dropper dependency to fetch platform-specific payloads.

StrongSwan Flaw Allows Unauthenticated Attackers to Crash VPNs

Integer underflow in StrongSwan EAP-TTLS parser allows unauthenticated remote DoS.

Axios Supply Chain Attack Pushes Cross-Platform RAT via Compromised npm Account

Axios npm package compromised via stolen credentials to deliver cross-platform RAT.

15-Year-Old strongSwan Flaw Lets Attackers Crash VPNs via Integer Underflow

15-year-old strongSwan integer underflow bug lets attackers crash VPNs via EAP-TTLS.

Telnyx Targeted in Growing TeamPCP Supply Chain Attack

TeamPCP compromises Telnyx Python SDK with malicious versions on PyPI targeting Windows, macOS, Linux.

TeamPCP Uses Fake Ringtone File in Tainted Telnyx SDK to Steal Credentials

TeamPCP injects malicious code into Telnyx Python SDK versions to steal credentials and crypto keys.

File read flaw in Smart Slider plugin impacts 500K WordPress sites

File read flaw in Smart Slider 3 WordPress plugin affects 500K sites via missing capability checks.

BeamMP, a popular mod for BeamNG Drive, was compromised. Internet nerds are investigating the se...

BeamMP mod for BeamNG Drive compromised and distributed malware to users.

🔴 THE UGLY | Supply Chain Compromise - TeamPCP Multi-Stage Attack: This week, attackers hijacke...

Attackers hijacked Trivy, npm, and LiteLLM packages in multi-stage supply chain campaign.

Backdoored Telnyx PyPI package pushes malware hidden in WAV audio

TeamPCP compromises Telnyx PyPI package with credential-stealing malware hidden in WAV files.

TeamPCP has done ANOTHER supply chain attack. My Brother in Christ, how many of these fuckin' th...

TeamPCP threat actor executes 50+ supply chain attacks across open-source packages in 8 days.

TeamPCP Pushes Malicious Telnyx Versions to PyPI, Hides Stealer in WAV Files

TeamPCP compromises telnyx PyPI package with stealer malware hidden in WAV files.

The #TeamPCP campaign continues. The telnyx #PyPI package (versions 4.87.1 & 4.87.2) with ~1M...

Telnyx PyPI package versions 4.87.1 & 4.87.2 compromised in TeamPCP campaign using WAV steganography.