keyv npm supply chain attack on August 4, 2026 let the Shai-Hulud worm compromise 400-plus packages and more than two billion ...
This is the OSS PR summary for 2026-08-05. The JST check time is `2026-08-05T06:24:14+09:00`, and the targets are `microsoft/fluentui-blazor`, `microsoft/fluentui`, `microsoft/aspire`, ...
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems ...
Kimi Code CLI Launcher for VS Code is a lightweight, unofficial VS Code extension that starts the Kimi Code CLI AI coding agent directly from the editor toolbar. One click opens kimi in a new side ...
[email protected] differs from [email protected] in three files: package.json, plus additions named setup.mjs and Math_Symbol.js. Nothing under dist/ changed. The compiled library a consumer imports ...
Afghan telecom providers and South Asian critical infrastructure organizations have emerged as the target of a new ongoing campaign that delivers a previously undocumented backdoor called PATCHCORD .
I know its been reported in the past #141214 and #139818 and those are marked closed at this point, but the tool tip is way to aggressive, it covers up the code around my pointer that I often use for ...