TypeScript, together with Node.js, is one of the most widely used web technologies. scriptc combines both in a native stack ...
More than 400 NPM packages have been infected with the Mini Shai-Hulud worm in the ChainDrop supply chain attack.
Aikido Security says an npm supply chain attack has infected Keyv packages with a variant of the credential-stealing ...
The Shai Hulud variant’s blast radius includes several highly popular packages thus far.. Security teams are urged to perform ...
Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly ...
Taking vibe-coding a step further, Naïve claims its infra can automate most of the work in setting up and running a business.
Upwind identified a malicious release of keyv@6.0.0 that harvested AWS, GitHub, and npm credentials via a hidden preinstall script. With 154 million weekly downloads, the compromise had ecosystem-wide ...
Enterprise AI workspace security gets a new open-source option: Cloudflare OS is a free, self-hostable platform where AI ...
New York, USA, August 4th, 2026, FinanceWireOpen-source software has long been built on trust. Developers routinely install ...
Union.ai today announced the general availability of Flyte 2, a ground-up rebuild of its open-source platform for AI and ML engineers. Flyte ...
Telnyx today launched Telnyx Edge Compute, the Agent Runtime that lets an entire real-time voice AI agent run on infrastructure Telnyx owns.
Open VSX removes 77 evil twin extensions that impersonate developer tools and exfiltrate host, workspace, Git, and CI data.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results