← heapsort-ai

malware

14 items

ARTICLEDEV.to AI·27d ago

The Worm in the Registry

A six-minute attack compromised the trust model of modern JavaScript development, pushing 84 malicious package versions across 42 @tanstack packages via a legitimate release pipeline. The "worm" spread to over 170 packages on npm and PyPI, affecting over 518 million cumulative downloads and targeting credential theft.

28
ARTICLEDEV.to AI·5/1/2026

TeamPCP resumes supply chain attacks, poisoning xinference PyPI and triggering a Bitwarden CLI cascade via compromised Docker image.

The TeamPCP supply chain campaign has resumed with concurrent compromises targeting the AI inference package xinference, Checkmarx KICS, and Bitwarden CLI. This directly impacts AI security by poisoning a widely used LLM/ML model serving framework and demonstrates sophisticated attack methods increasingly intersecting with AI tooling.

27
ARTICLEDEV.to AI·10d ago

AI Detector: How to Build a Malicious Model Sniffer

The article introduces slop-squatting, a supply-chain attack that exploits hallucinated software package names generated by large language models. It details how attackers register phantom packages to distribute malicious code and discusses building a scanner to detect these AI-generated attacks.

27
NEWSDEV.to AI·4/8/2026

Suspicious Skills — What to Watch — 2026-04-08

Um relatório recente sobre habilidades digitais revela que, de 52.702 habilidades indexadas e 2.105 auditadas, 172 foram identificadas como maliciosas e 1.012 como suspeitas. O conteúdo convida à leitura do relatório completo e oferece ferramentas para auditoria e verificação de segurança.

21
ARTICLEDEV.to AI·25d ago

VanillaRat 1.7

VanillaRAT 1.7 has emerged as a sophisticated Remote Access Trojan (RAT). It possesses enhanced capabilities for stealthy system infiltration and persistent control.

9
DOCDEV.to AI·4/9/2026

Audit Coverage Report — 2026-04-09

O relatório de auditoria de 09/04/2026 detalha que 54.454 skills foram indexadas, com 2.105 auditadas, resultando na identificação de 172 maliciosas e 1.012 suspeitas. O documento fornece links para o relatório completo, busca e verificações de pré-instalação.

9