
Shai-hulud npm attack: What you need to know
RL researchers detected the first self-replicating worm that compromised npm packages with cloud token-stealing malware. Here's what you need to know.

Reverse Engineer at ReversingLabs

RL researchers detected the first self-replicating worm that compromised npm packages with cloud token-stealing malware. Here's what you need to know.

The eslint-config-prettier package exposed more than 10,000 dependent projects. The incident highlights the growing risks in automated dependency updating.

RL researchers detected a new malicious campaign that exploits the Pickle file format on the Python Package Index.

RL researchers detected a sophisticated, malicious package believed to be an ongoing campaign that may be linked to a hacktivist gang.

A new Python package revives the name of a malicious module to steal source code and secrets from blockchain developers’ machines.

Software development teams working on machine learning take note: RL threat researchers have identified nullifAI, a novel attack technique used on Hugging Face.

A compromised build environment led to a malicious deployment of a popular AI library that had the potential of delivering other malware.

The incident demonstrates how machine learning-based threat hunting can help development teams spot threats other tools miss.

RL found the VMConnect campaign continuing with malicious actors posing as recruiters, using packages and the names of financial firms to lure developers.
Get your 14-day free trial of Spectra Assure
Get Free TrialMore about Spectra Assure Free Trial