Category: Secrets Security

JulesJacker: Fake npm Worm Impersonates Jules AI

JulesJacker: A Fake-PoC npm Worm That Impersonates Google’s Jules Agent — and Turns on the Sandbox Analyzing It

RuntimeBroker npm Typosquat Plants Crypto Clipper

RuntimeBroker: an npm Typosquat Plants a 40-Chain Crypto-Clipper as a Cross-OS \”System Runtime Helper”\

AuditorTrap

AuditorTrap: A 22-Package Fake Crypto Security Guild on npm With Two Parallel Payloads

PhantomBot From Credential Theft to Botnet

PhantomBot: A Typosquat Campaign That Pivoted From Credential Theft to a Turnkey Botnet Kit

AWS Lambda npm Dependency Confusion Attack The 24712-pl Campaign

AWS Lambda npm Dependency Confusion Attack: The 24712-pl Campaign

alone5511 npm Dependency Confusion Attack

alone5511 npm Dependency Confusion Attack

AI Security Risks in DevSecOps

AI Security Risks in DevSecOps: Code, Pipelines, and Agents

EVMDeFi npm Typosquatting Attack Steals Developer Keys

EVM/DeFi npm Typosquatting Attack Steals Developer Keys

FauxCode When Your Reverse-Engineered Claude Code Quietly Routes Through the Attacker

FauxCode: Reverse-Engineered Claude Code Routes Through Attackers

DevTap npm Typosquatting Attack

DevTap npm Typosquatting Attack: Six Malicious Packages Target Developer Workstations

LiteLLM Supply Chain Attack

LiteLLM Attack: How Xygeni Stops Secret Exposure Fast

dockerfile secrets - dockerfile secrets environment variables

Dockerfile Secrets: Why Layers Keep Your Sensitive Data Forever