Back to Feed

Tag

Open Source

OSS vulnerabilities, package security, dependency risks

50 items tagged #open-source

Articles

Malicious Postinstall Hook Found Across 700+ GitHub Repositories, Including Packagist and Node.js Projects

Malicious postinstall hooks discovered across 700+ GitHub repos targeting PHP and Node.js packages via Packagist.

RT @CISACyber: 🛡️ We added Drupal core SQL injection vulnerability CVE-2026-9082 to our KEV Cata...

CISA adds Drupal core SQL injection vulnerability CVE-2026-9082 to KEV catalog

AI Has Taken Over Open Source

AI-generated packages surge exponentially on npm, reshaping open source production and consumption.

GitHub links repo breach to TanStack npm supply-chain attack

GitHub breach of 3,800 repos linked to malicious Nx Console extension in TanStack npm supply-chain attack

Socket raises $60M Series C at a $1B valuation to secure software supply chains for AI-driven development

Socket raises $60M Series C at $1B valuation to defend software supply chains against AI-era attacks.

New Shai-Hulud malware wave compromises 600 npm packages

Shai-Hulud campaign injects malware into 600+ npm packages to steal developer credentials.

Leaked Shai-Hulud malware fuels new npm infostealer campaign

Leaked Shai-Hulud malware deployed in four malicious npm packages by threat actor.

First Shai-Hulud Worm Clones Emerge

Shai-Hulud worm clones emerge days after source code release on GitHub.

Grafana Says It Rejected Ransom Demand After Source Code Theft

Grafana confirms source code theft via compromised GitHub token; rejects ransom demand.

Funnel Builder WordPress plugin bug exploited to steal credit cards

Funnel Builder WordPress plugin vulnerability exploited to inject payment card skimmers.

TeamPCP Ups the Game, Releases Shai-Hulud Worm’s Source Code

TeamPCP releases Shai-Hulud worm source code on GitHub, fueling supply chain attacks with monetary rewards.

TeamPCP hackers advertise Mistral AI code repos for sale

TeamPCP hackers demand $25K for stolen Mistral AI source code via supply-chain compromise.

‼️🇺🇸⚡ Lightning AI allegedly breached: internal codebase and project files exposed from the cre...

Lightning AI allegedly breached; internal codebase and PyTorch Lightning project files exposed.

Stealer Backdoor Found in 3 Node-IPC Versions Targeting Developer Secrets

Stealer backdoor discovered in 3 node-ipc npm package versions targeting developer credentials.

18-year-old NGINX vulnerability allows DoS, potential RCE

18-year-old NGINX heap buffer overflow vulnerability allows DoS and potential RCE.

PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours of Disclosure

PraisonAI CVE-2026-44338 auth bypass exploited within hours of disclosure

TeamPCP and BreachForums Launch $1,000 Contest for Supply Chain Attacks

TeamPCP and BreachForums launch $1,000 contest rewarding supply chain attacks on open source packages.

Security advisories | Mistral Docs

TanStack supply chain attack compromises Mistral AI SDK packages on npm and PyPI

‼️🇫🇷 Mistral AI has confirmed they were impacted by the recent TanStack supply chain attack. h...

Mistral AI confirms impact from TanStack supply chain attack.

Attackers Weaponize RubyGems for Data Dead Drops

Threat actors publish malicious RubyGems packages with scrapers targeting UK government servers.

New critical Exim mailer flaw allows remote code execution

Critical Exim mail server flaw CVE-2026-45185 allows unauthenticated remote code execution via TLS handling.

TeamPCP Used Mini Shai-Hulud Worm to Poison Over 400 npm and PyPI Packages

TeamPCP poisoned 400+ npm and PyPI packages with Mini Shai-Hulud self-propagating worm via hijacked OIDC tokens.

Packagist Urges Immediate Composer Update After GitHub Actions Token Leak

Composer vulnerability exposed GitHub Actions tokens in CI logs due to token format validation regex mismatch.

GemStuffer Abuses 150+ RubyGems to Exfiltrate Scraped U.K. Council Portal Data

GemStuffer campaign abuses 150+ RubyGems packages to exfiltrate U.K. council portal data.

Hundreds of Malicious Packages Force RubyGems to Suspend Registrations

RubyGems suspends new registrations after 500+ malicious packages uploaded in attack.

‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supply-chain attack

Mini Shai-Hulud malware compromises hundreds of open-source packages across major registries in supply-chain attack.

New Exim BDAT Vulnerability Exposes GnuTLS Builds to Potential Code Execution

Exim BDAT use-after-free vulnerability (CVE-2026-45185) enables RCE in GnuTLS builds.

Good news everyone Shai-Hulud, that spoopy Git worm thingy everyones been yapping about, has bee...

Shai-Hulud Git worm malware code publicly released on GitHub.

RubyGems Suspends New Signups After Hundreds of Malicious Packages Are Uploaded

RubyGems suspends signups after 500+ malicious packages uploaded in coordinated attack.

Hugging Face Packages Weaponized With a Single File Tweak

Hugging Face tokenizer files can be manipulated to hijack AI model outputs and exfiltrate data.

Shai Hulud attack ships signed malicious TanStack, Mistral npm packages

Shai-Hulud campaign compromises 160+ npm packages with credential-stealing malware via OIDC token hijacking.

Worm Redux: Fresh Mini Shai-Hulud Infections Bite Supply Chain

Hundreds of npm packages infected by self-propagating worm targeting TanStack ecosystem.

TanStack, Mistral AI, UiPath Hit in Fresh Supply Chain Attack

TeamPCP compromises 170+ npm/PyPI packages in Mini Shai-Hulud supply chain attack.

Following the initial report from @wiz_io on compromised MistralAI packages, our artifact‑scannin...

Shai Hulud malware discovered in additional compromised MistralAI NPM packages for GCP and Azure.

Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages

TeamPCP compromises npm/PyPI packages from TanStack, Mistral AI, Guardrails AI via Mini Shai-Hulud worm campaign.

We analyzed Heartflabrace/Doubao-Claw A malicious "AI skill" posing as a Volcengine/ByteDance Do...

Zscaler discovers malicious AI skill posing as ByteDance Doubao CLI in OpenClaw ecosystem.

Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads

Fake OpenAI Privacy Filter repo on Hugging Face delivers Rust infostealer, hits #1 trending with 244K downloads.

‼️🇧🇩 BADC allegedly breached exposing full private git repo from Bangladesh Agricultural Develo...

BADC private git repository allegedly breached and leaked by threat actor.

Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak

Critical out-of-bounds read in Ollama allows remote memory leak affecting 300K+ servers.

Fake OpenAI repository on Hugging Face pushes infostealer malware

Malicious Hugging Face repository impersonating OpenAI's Privacy Filter delivers infostealer malware.

Gemini CLI Vulnerability Could Have Led to Code Execution, Supply Chain Attack

Gemini CLI vulnerability allowed prompt injection to enable supply chain attacks via GitHub issues.

‼️🏴‍☠️ Nimrod Stealer source code allegedly shared on a hacking forum for credential and browser...

Nimrod Stealer source code leaked on hacking forum for credential theft.

Critical vm2 sandbox bug lets attackers execute code on hosts

Critical vm2 sandbox escape vulnerability (CVE-2026-26956) allows arbitrary code execution on host systems.

OceanLotus suspected of using PyPI to deliver ZiChatBot malware

OceanLotus deploys ZiChatBot malware via malicious PyPI packages targeting Windows and Linux.

Critical Bug Could Expose 300,000 Ollama Deployments to Information Theft

Critical heap out-of-bounds read in Ollama exposes 300K deployments to unauthenticated information theft.

MetInfo CMS CVE-2026-29014 Exploited for Remote Code Execution Attacks

MetInfo CMS CVE-2026-29014 actively exploited for unauthenticated remote code execution

Backdoored PyTorch Lightning package drops credential stealer

Malicious PyTorch Lightning v2.6.3 on PyPI deploys credential-stealing JavaScript payload.

Wiz ZeroDay.Cloud Event Reveals 20-Year-Old PostgreSQL Vulnerabilities

Researchers reveal 20-year-old PostgreSQL flaws in pgcrypto at Wiz ZeroDay.Cloud event.

I have posted several of these, here is another cPanel/WHM PoC... CVE-2026-41940: cPanel/WHM Aut...

PoC released for CVE-2026-41940, cPanel/WHM authentication bypass vulnerability.

The Good, the Bad and the Ugly in Cybersecurity – Week 18

Threat actors poison SAP npm packages to steal developer credentials in supply chain attack.