IntroductionOn May 14, 2026, the Zscaler ThreatLabz team identified unusually high activity associated with the threat actor SmartApeSG to deploy malware. During our examination, we discovered ...
A poisoned npm package infected 140+ projects with a hidden payload. This report highlights how to detect, hunt, and defend ...
ClickFix attacks are delivering BabaDeda, Lorem Ipsum, and Potemkin loaders to deploy stealers, RATs, and ransomware-linked ...
Chainguard will use AI to protect open-source code. Athena pools open-source users, developers, and maintainers. Others are ...
July 2026, blocking install scripts, Git dependencies, and remote URL sources by default. Every team running npm install in ...