While the AI itself wasn’t weaponized, the technique raises concerns about AI agents with broad system access.
Someone compromised open source AI coding assistant Cline CLI's npm package earlier this week in an odd supply chain attack ...
Here's how the JavaScript Registry evolves makes building, sharing, and using JavaScript packages simpler and more secure ...
The malicious version of Cline's npm package — 2.3.0 — was downloaded more than 4,000 times before it was removed.
The npm registry now includes Socket security analysis links directly on package pages to help developers assess supply chain risks.
North Korea-linked Lazarus campaign spreads malicious npm and PyPI packages via fake crypto job offers, deploying RATs and data-stealing malware.
TypeScript 6.0 is intended to be the last release based on the current JavaScript codebase, before a Go-based compiler and language service debuts in TypeScript 7.0.
Researchers have revealed that bad actors are targeting dYdX and using malicious packages to empty its user wallets.
North Korean IT operatives use stolen LinkedIn accounts, fake hiring flows, and malware to secure remote jobs, steal data, ...
A new variation of the fake recruiter campaign from North Korean threat actors is targeting JavaScript and Python developers ...
Local AI agents and a gaming handheld - what could possibly go wrong?
Building your perfect programming environment is easier than you think. Here's how to do it in minutes!