Chainguard, the trusted foundation for software development and deployment, today announced Chainguard Libraries for JavaScript, a collection of trusted builds of thousands of common JavaScript ...
Chainguard Libraries for JavaScript include builds that are malware-resistant and built from source on SLSA L2 infrastructure ...
The novel malware strain is being dubbed Shai-Hulud — after the name for the giant sandworms in Frank Herbert’s Dune novel ...
Newly discovered npm package 'fezbox' employs QR codes to hide a second-stage payload to steal cookies from a user's web browser. The package, masquerading as a utility library, leverages this ...
In light of recent cyberattacks and growing security concerns, GitHub is taking immediate and direct action to secure the ...
Process improvements and a closer look at funding streams will provide far more protection for the open source software we ...
Dozens of npm libraries, including a color library with over 2 million downloads a week, have been replaced with novel ...
The foundations said in their blog post that automated CI systems, large-scale dependency scanners, and ephemeral container ...
Hackers planted malicious code in open source software packages with more than 2 billion weekly updates in what is likely to ...
Two malicious packages with nearly 8,500 downloads in Rust's official crate repository scanned developers' systems to steal ...
Charles Guillemet says a phishing-led supply-chain breach could have become a systemic disaster for crypto users.
North Korean-linked crews connected to the pervasive IT worker scams have upped their malware game, using more advanced tools ...