Topic: developer security
-
North Korean Hackers Behind Rust Supply Chain Attack
North Korean state-sponsored hackers (tracked as Sapphire Sleet) compromised three popular Rust crates,arrayref, internment, and append-only-vec,by hijacking a maintainer's account and injecting a typosquatted dependency (proc-macro1) that executed malicious code during the build process. The att...
Read More » -
Old Trick Still Works: AI Coding Tools Hacked via Decades-Old Technique
Security researchers at Wiz have identified a novel attack called GhostApproval that exploits AI coding assistants by manipulating how they process and approve code suggestions, tricking the tool into executing harmful actions on a developer's machine. The vulnerability stems from the AI tool's t...
Read More » -
Popular OpenAI Codex tool with 29k weekly downloads stole dev tokens for a month
A malicious npm package named "codexui-android", with 29,000 weekly downloads and a legitimate appearance, secretly exfiltrated developer authentication tokens for at least a month. The supply chain attack worked by silently reading local credential files each time the package was executed, with ...
Read More » -
GitHub Confirms 3,800 Repos Breached via Malicious VSCode Extension
A GitHub employee's device was compromised after installing a malicious VS Code extension, leading to approximately 3,800 internal repositories being accessed by attackers. The hacker group TeamPCP claimed responsibility and is demanding a minimum of $50,000 for the stolen code, threatening to le...
Read More » -
PhantomRaven NPM Attack Steals Dev Data in 88 Packages
The PhantomRaven campaign targets the npm registry using malicious packages that employ tactics like 'slopsquatting' and Remote Dynamic Dependencies to evade detection and steal developer data. Once installed, the malware harvests sensitive information, including developer credentials, CI/CD plat...
Read More » -
Escape Secures $18M to Scale AI-Powered Security Automation
Escape raised $18 million in Series A funding to expand its AI-driven platform, which autonomously hunts for vulnerabilities in live production systems, a critical gap left by traditional pre-deployment security tools. The platform uses continuous AI agents to automate the security lifecycle, rep...
Read More » -
Belgian Cybersecurity Startup Aikido Reaches Unicorn Status
Aikido Security, a Belgian cybersecurity startup founded in 2022, has achieved a $1 billion valuation after a $60 million Series B funding round, marking the fastest rise to unicorn status for a European cybersecurity company. The company's success is built on a developer-first platform that inte...
Read More » -
Critical Zero-Day Threat for Cursor & Windsurf Users Exposed
A zero-day vulnerability in AI coding tools (e.g., Cursor, Windsurf) exposed developers to machine hijacking via compromised extensions, with attackers exploiting OpenVSX's automated publishing system. The flaw, dubbed VSXPloit, allowed attackers to push malicious updates silently through depende...
Read More »