Axios Compromise on npm Introduces Hidden Malicious Package
A newly discovered software supply chain attack targeting the npm ecosystem briefly compromised one of the most widely used...
A newly discovered software supply chain attack targeting the npm ecosystem briefly compromised one of the most widely used...
This morning, the widely used Python package litellm, a popular abstraction layer for interacting with large language models (LLMs),...
Sonatype Security Research has identified a potential compromise of a trusted npm maintainer account that has now published two...
Sonatype Security Research has identified two hijacked npm packages in the React Native ecosystem that receive more than 30,000...
Earlier this year, we asked our team where they expect open source cyberattacks to go next. Sonatype Principal Security...
Earlier this year, we asked our team where they expect open source cyberattacks to go next. Sonatype Principal Security...