StubMaker Malware Campaign Hit RubyGems and npm With the Same Windows Infostealer
Researchers found one threat actor ran typosquatting campaigns on RubyGems and npm days apart, sharing an identical Rust loader and Go infostealer.
Signal
30 articles covering "supply chain security"
Researchers found one threat actor ran typosquatting campaigns on RubyGems and npm days apart, sharing an identical Rust loader and Go infostealer.
GitHub now feeds Dependabot malware alerts from OpenSSF's malicious-packages data across npm, PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer.
Wiz's autonomous Red Agent found and exploited a GitHub Actions injection flaw in a Snowflake repo that GitHub's own scanner had missed, exfiltrating a live Jira token.
A CVSS 9.8 Gitea flaw let unauthenticated users read server files via Org-mode markup; XBOW Security's autonomous system found it.
Mozilla revoked and replaced a GPG signing subkey after an unencrypted copy leaked into a private GitHub repo, finding no evidence of unauthorized use.
Sonatype found six npm packages that decode malware C2 server IPs from Ethereum transaction bytes, using a technique tied to North Korea's Contagious Interview campaign.
GitHub detailed a technical-preview Actions network firewall and rounded up npm and Actions defaults changed since February, drawing sharp Hacker News debate over delay-based defenses versus package signing.
Five banks piloted a shared open source patching alliance; FINOS says AI-accelerated vulnerability discovery makes mutualized fixes urgent.
Dependabot now waits three days before proposing new dependency versions by default. GitHub says the delay keeps freshly compromised releases out of update pull requests; security updates are exempt and repositories can opt out.
npm v12 disables install scripts, Git dependencies, and remote-URL dependencies by default, closing the execution path several npm worms exploited over the past year.
GitHub's new License Compliance feature enters public preview, letting Enterprise Cloud customers with GitHub Advanced Security block pull requests that add dependencies violating license policy.
Bundler 4.0.13's cooldown filter excludes brand-new gem versions from dependency resolution to blunt supply-chain attacks that exploit the minutes after a malicious release.