Risky Business: The Anti-Proctoring Packages That Delete Themselves

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.
Cyber Threats Explained: The Main Types Security Teams Should Know

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.
The npm Worm Playbook: Same Attack, Three Times in Eight Months

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.
JavacDoor: A Maven Artifact That Ran During Compilation, Not Installation

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.
Npm Supply Chain Attacks: Biggest Incidents & How to Stop Them

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.
How AI Agents Can Automate a Ransomware Attack: What JadePuffer Just Proved

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.
QuietPolyfill: An NPM dropper that resurrected

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.
Rogue by Design: How a Sandboxed Pre-Release Model Jailbroke Itself and Hacked Hugging Face to Cheat an Exam

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.
PointBlank: a fully-featured Python RAT that ran its command channel through a free note-hosting service

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.
Slopsquatting evolution: From AI Curiosity to Agent RCE

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.
PhantomSync: eight crypto-developer npm packages hide a delayed, self-persisting dropper

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.
FauxUV: fake PyPI uv helpers that open an unauthenticated Jupyter server to the internet

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.