Vidar, a well-known information-stealing malware family first seen in 2018, has introduced new string-obfuscation methods ...
Blackpoint uncovers ChainScript, a Node.js RAT that queries a Polygon smart contract to find and rotate its command server.
A malicious npm package reached over 2 million weekly downloads by hiding its payload in a routine library function rather than an install script.
A new npm supply chain campaign is hiding malware inside ordinary JavaScript package code instead of using the usual ...
Two OpenAI Codex sandbox flaws, Overpatch and Heapjack, could let malicious repositories execute commands on developer systems.
An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by ...
Researchers escaped OpenAI's Codex sandbox two ways, one running commands on a developer's machine from its most locked-down mode. OpenAI has patched both.
Released on September 3, 2026, GPT-6 Astra is OpenAI’s powerful flagship AI model with numerous capabilities and has already ...