A Supply-Chain Worm Wrote Itself Into Claude Code's Hook Files to Survive Credential Rotation
Rotating your credentials and removing a poisoned package is supposed to end an npm supply-chain compromise. In early August 2026, one worm made sur…
Tech news from the best sources
Rotating your credentials and removing a poisoned package is supposed to end an npm supply-chain compromise. In early August 2026, one worm made sur…
When people hear about JINGDONG Logistics, also known as JD Logistics, they may think of package delivery. But delivery is only one part of what the…
Every admission webhook you rely on has an escape hatch. Nothing scandalous about that, it is just how Kubernetes wires them up. A CNCF post on July…
PyPI now rejects new file uploads against any release older than 14 days, closing off a small but useful window that a compromised publishing token…
What Happened This week, Booking.com confirmed that unauthorized third parties accessed reservation data belonging to a subset of customers. Exposed…
Every time your bot merges a two-hour-old release into main, you are trusting a stranger's freshly published tarball to be the same one everyone els…
Your platform team ships an internal package. Half the org pulls it. Someone finds a bug that in the wrong hands is a full RCE. What do you do next:…
Until now, the tools that install packages have never once stopped to ask, "Are you sure it's okay to take this one?" Whether it's pip install or np…
The npm incident, but for AI agents Remember when malicious npm packages stole crypto wallets? The same thing is coming for MCP servers. An MCP serv…
un Trivy against almost any vendor container image and you'll get a wall of findings. Most of them don't matter, the vulnerable code path is never e…
Every open-source CVE backlog has that one line item you keep sliding into next quarter. The library is a couple of majors behind, the upgrade break…
Your CI catches the npm vulnerability. Your developer is already three branches away and one standup behind. The package is installed, the lockfile…
The previous parts of this series were written from a comfortable distance. I read the Trend Micro diagrams about Shai-Hulud, I theorised about Dock…
Every open source project's CI pipeline is a quiet confession of how much trust it extends to its own contributors. (Most maintainers would rather y…
Your CI runner is a stranger with a credit card and root. Every brew install against a third-party tap is the same trust gesture as curl | sh , just…
The npm account ai publishes seven packages. Combined, they install 964 million times per week: Package Weekly downloads Publishers Risk postcss 245…
On June 3, JFrog Security Research published their analysis of IronWorm — a supply chain attack that compromised 37 npm packages through the asteroi…
We’ve treated local AI deployments as experimental toys for too long. The moment a homelab becomes a dependency for work, the security posture must…
ShadowFeed Weekly #1 | Web3 Security Intelligence June 5 — June 11, 2026 ShadowFeed is a real-time Web3 security intelligence service for developers…
Introduction and Background The Rust ecosystem, celebrated for its memory safety and performance, relies heavily on crates —its package management s…
GitHub is not just a source code platform anymore. For most engineering organizations, GitHub is part identity system, part software supply chain, p…
This article was originally published on LucidShark Blog . On May 29, 2026, a developer pushed a new release of jqwik, a popular Java property-based…
By Ionut-Cristian Florescu ( @icflorescu ), written June 6, 2026, while still locked out. How the Miasma worm, a Shai-Hulud strain that this week al…
In neighbourhood retail markets, local Kirana stores, and hyper-local fulfilment centres, inventory management isn’t an administrative task—it’s a h…
The MCP ecosystem has been growing fast, but the supply-chain hygiene has not kept up. MCPwn (CVE-2026-33032, CVSS 9.8) exposed 2,600+ instances. Th…
On April 29th, Aikido researchers detected multiple compromised Node.js packages in SAP's namespace today. The malware adapts to CI environments, st…
Socket Security flagged a campaign yesterday: roughly 700 GitHub repositories carrying a poisoned package.json that drops /tmp/.sshd , pipes curl -s…
Originally posted on getcommit.dev . In October 2021, ua-parser-js was used by Facebook, Microsoft, Amazon, and Google. It had 7 million weekly down…
Gulf Conflict Triggers New PCB Supply Chain Crisis A convergence of geopolitical disruption and commodity price surges is creating the PCB industry'…
Wire Fire — Episode 02 On 18 May 2026 an attacker published a poisoned version of a popular Visual Studio Code extension. It was live for roughly el…