DeviceDoor: a public npm package shipping a Microsoft 365 device-code phishing and bulk-mail framework

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.
OWASP Global AppSec EU 2026 Vienna: Key Takeaways on Secure Software Supply Chain, MCP Security, and the AI-BOM

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.
AI Security at OWASP Global AppSec EU 2026: Meet Xygeni in Vienna

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.
CryptoDAO Confusion: eleven npm packages, one payload, harvesting CI/CD and crypto-wallet secrets

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.
Permission Slip: An npm “Authorized Research” Cover Story Hiding Cloud-Metadata Probes and SYSTEM Persistence

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.
Ectoplasm: npm install hooks that harvest AWS credentials behind a container-only trigger

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.
SeedSweep: Ten Crypto-Themed npm Packages That Only Run When No One Is Watching

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.
PairLoop: One npm Package, Seventy Versions, and a Hidden Windows Remote-Control Panel

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.
ConsentMask: An npm Package That Wears a Telemetry Consent Banner Over Developer-Identity Harvesting

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.
JulesJacker: A Fake-PoC npm Worm That Impersonates Google’s Jules Agent — and Turns on the Sandbox Analyzing It

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.
RuntimeBroker: an npm Typosquat Plants a 40-Chain Crypto-Clipper as a Cross-OS \”System Runtime Helper”\

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.
AuditorTrap: A 22-Package Fake Crypto Security Guild on npm With Two Parallel Payloads

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.