The typosquatted “@acitons/artifact” package targeted GitHub’s CI/CD workflows, stealing tokens and publishing malicious ...
A critical vulnerability in the popular expr-eval JavaScript library, with over 800,000 weekly downloads on NPM, can be ...
The coordinated campaign has so far published as many as 46,484 packages, according to SourceCodeRED security researcher Paul ...
Goal is to steal Tea tokens by inflating package downloads, possibly for profit when the system can be monetized.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results