Microsoft Threat Intelligence said attackers placed malicious code inside a Mistral AI download distributed through a Python ...
TanStack had 2FA, OIDC publishing, and Sigstore provenance on every release. The Mini Shai-Hulud worm published 84 malicious ...
Attackers compromised the official Mistral AI Python package on PyPI along with hundreds of other widely-used developer packages, exposing GitHub tokens, ...
If you’ve downloaded the Cemu Wii U emulator for Linux from the project’s official GitHub in the past few weeks, bad news: it added malware to your system when you ran it. An announcement made by the ...
The CEMU development team has made an urgent security announcement, revealing that compromised files had been spread via its ...
An attacker poisoned 84 TanStack npm versions across 42 packages, stealing GitHub OIDC tokens and cloud keys while planting a ...
Microsoft says attackers compromised the mistralai PyPI package with malware that executed on import, while researchers link ...
Over 170 TanStack, Mistral AI, OpenSearch, UiPath, and other packages were affected in a new Mini Shai-Hulud supply chain ...
TeamPCP’s Mini Shai-Hulud campaign used hijacked GitHub OIDC tokens to spread a credential-stealing worm through TanStack npm ...
Between May 6 and 7, it was dangerous to install JDownloader from alternative links on the site.
The repository reached the #1 trending position on Hugging Face within 18 hours, highlighting how public AI repositories are ...
In early May, the JDownloader website delivered malware. This is reminiscent of Daemon Tools, which have since reacted.