Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
varunsharma07
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
The State of Open Source Supply Chain Attacks
(stepsecurity.io)
1 points
by
varunsharma07
24d ago
|
0 comments
2.
▲
by
varunsharma07
1mo ago
We (StepSecurity) published a full analysis of both payload stages: https://www.stepsecurity.io/blog/chaindrop-npm-worm Some additional detail from our analysis: 1. Provenance did not fail, it worked as designed and st
3.
▲
Immobiliarelabs NPM packages have been compromised
(github.com)
2 points
by
varunsharma07
3mo ago
|
0 comments
4.
▲
Codfish/semantic-release-action GitHub Action has been compromised
(stepsecurity.io)
4 points
by
varunsharma07
3mo ago
|
0 comments
5.
▲
Multiple mastra NPM packages compromised
(github.com)
4 points
by
varunsharma07
3mo ago
|
1 comments
6.
▲
by
varunsharma07
3mo ago
Mastra is an open-source TypeScript framework for building AI agents, workflows, and RAG pipelines. The StepSecurity Threat Intelligence Team has identified that multiple mastra npm packages have been compromised.
7.
▲
Ongoing NPM supply chain attack uses binding.gyp to spread like a worm
(github.com)
6 points
by
varunsharma07
4mo ago
|
0 comments
8.
▲
Laravel-Lang Supply Chain Attack
(github.com)
3 points
by
varunsharma07
4mo ago
|
1 comments
9.
▲
by
varunsharma07
4mo ago
On May 22, 2026, an attacker with push access to the Laravel-Lang GitHub organization rewrote every git tag across multiple popular Composer packages within a single 15 minute window.
10.
▲
NX VS Code extension compromised again
(github.com)
4 points
by
varunsharma07
4mo ago
|
0 comments
11.
▲
Actions-cool/issues-helper GitHub Action Compromised
(github.com)
3 points
by
varunsharma07
4mo ago
|
0 comments
12.
▲
Malicious node-IPC Versions Published to NPM
(github.com)
6 points
by
varunsharma07
4mo ago
|
2 comments
13.
▲
by
varunsharma07
4mo ago
We have built an AI Package Analyst https://app.stepsecurity.io/oss-security-feed and also monitor them using https://github.com/step-security/harden-runner for runtime behavior.
14.
▲
by
varunsharma07
4mo ago
@mistralai/mistralai npm package was also compromised as part of this worm https://github.com/mistralai/client-ts/issues/217 It has been pulled from the npm registry now.
15.
▲
Postmortem: TanStack NPM supply-chain compromise
(tanstack.com)
1097 points
by
varunsharma07
4mo ago
|
465 comments
16.
▲
by
varunsharma07
4mo ago
The Mini Shai-Hulud worm is actively compromising legitimate npm packages by hijacking CI/CD pipelines and stealing developer secrets. StepSecurity's OSS Package Security Feed first detected the attack in official @tanstack packag
17.
▲
by
varunsharma07
6mo ago
The StepSecurity threat intelligence team discovered that dev-protocol — a verified GitHub organization with 568 followers belonging to a legitimate Japanese DeFi project — has been hijacked and is now being used to distribute malicious Pol
18.
▲
Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push
(stepsecurity.io)
5 points
by
varunsharma07
6mo ago
|
1 comments
19.
▲
by
varunsharma07
6mo ago
An attacker is compromising hundreds of GitHub accounts and injecting identical malware into hundreds of Python repositories. The earliest injections date to March 8, 2026, and the campaign is still active with new repos continuing to be co
20.
▲
Show HN: Scan your dev machine for AI agents, MCP servers, and IDE extensions
(github.com)
9 points
by
varunsharma07
6mo ago
|
0 comments
21.
▲
Xygeni/xygeni-action GitHub Action is compromised – poisoned tag is still live
(stepsecurity.io)
2 points
by
varunsharma07
6mo ago
|
0 comments
22.
▲
by
varunsharma07
7mo ago
The root cause is workflows that grant trust to untrusted inputs: pull_request_target that checks out and executes fork code with repo secrets, ${{ }} expressions that interpolate branch names/filenames into shell commands unsanitized,
23.
▲
Hackerbot-Claw: AI Bot Exploiting GitHub Actions – Microsoft, Datadog Hit So Far
(stepsecurity.io)
27 points
by
varunsharma07
7mo ago
|
4 comments
24.
▲
by
varunsharma07
7mo ago
We analyzed an autonomous bot (hackerbot-claw) that's actively scanning GitHub repos for exploitable Actions workflows. It hit Microsoft, DataDog, a CNCF project, and awesome-go (140k stars) achieving RCE in 4 out of 5 targets and exfi
25.
▲
GitHub Actions is left vulnerable to supply chain attacks: Datadog Report
(datadoghq.com)
4 points
by
varunsharma07
7mo ago
|
0 comments
26.
▲
Cline Supply Chain Attack: Cline 2.3.0 Silently Installs OpenClaw
(stepsecurity.io)
12 points
by
varunsharma07
7mo ago
|
1 comments
27.
▲
by
varunsharma07
7mo ago
cline@2.3.0 was published with a malicious post-install script that silently installs OpenClaw on any machine running npm install.
28.
▲
Harden Runner Detected the SHA1-Hulud Supply Chain Attack in CNCF's Backstage
(stepsecurity.io)
1 points
by
varunsharma07
10mo ago
|
1 comments
29.
▲
by
varunsharma07
10mo ago
A case study on detecting npm supply chain attacks through runtime monitoring and baseline anomaly detection
30.
▲
by
varunsharma07
1y ago
Thanks! I had also posted on HN 9 hours before this submission: https://news.ycombinator.com/item?id=45035115 Would be great if HN admins can update the link for this story
More ›