Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
Compromised jscrambler 8.14.0: Rust Infostealer Detection and Remediation
Compromised jscrambler 8.14.0: Rust Infostealer Detection and Remediation Date: July 11, 2026 Author: Senior Security Consultant, Security A...
Multi-Ecosystem Supply Chain Attack: npm & PyPI Typosquatting Campaign Targeting Payment SDKs
Intelligence Briefing: Multi-Ecosystem Supply Chain Attack Threat Summary AlienVault OTX has detected a coordinated supply chain attack targ...
Meta Business Manager Phishing & PyPI/NPM Supply Chain Attack — OTX Pulse Analysis
Meta Business Manager Phishing & PyPI/NPM Supply Chain Attack — OTX Pulse Analysis Excerpt: Active credential theft via npm/PyPI typosquatti...
Supply Chain Threat: Detecting npm Hijacking via VSCode Autorun and Blockchain Dead Drops
Introduction The latest Security Affairs malicious software newsletter highlights a concerning evolution in software supply chain attacks: t...
North Korea-Linked npm Supply Chain Attack: Rollup Polyfill Mimicry Detection
North Korea-Linked npm Supply Chain Attack: Rollup Polyfill Mimicry Detection Introduction A sophisticated supply chain attack has been iden...
PolinRider Campaign: Defending Against North Korean Supply Chain Attacks in npm, Go, and Chrome
Introduction The threat landscape for software development environments has deteriorated significantly with the emergence of the PolinRider ...
Supply Chain Alert: Hijacked npm and Go Packages Using VS Code Tasks to Deploy Python Infostealers
Introduction In June 2026, JFrog security researchers uncovered a sophisticated supply chain attack targeting the open-source ecosystem. Thi...
Miasma Supply Chain Attack: Detection and Remediation for npm and GitHub Actions Abuse
Introduction The open-source supply chain remains a primary vector for sophisticated adversaries in 2026. Security researchers have identifi...
Miasma Campaign: Detecting npm Supply Chain Attacks Bypassing SLSA Level 3
Introduction The Miasma campaign marks a disturbing evolution in open-source supply chain warfare. By leveraging a stolen session cookie tha...