

CSO Online: Supply-chain attacks take aim at your AI coding agents

Infosecurity: Malicious npm Dependency Linked to AI Assisted Commit Targets Crypto Wallets

Hackread: GraphAlgo Scam: Lazarus Hackers Register Real US LLCs to Spread Malware

SecurityWeek: Axios NPM Package Breached in North Korean Supply Chain Attack

Hackread: New Ghost Campaign Uses Fake npm Progress Bars to Phish Sudo Passwords

Hacker News: Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials

Tech Radar: North Korean job scammers target JavaScript and Python developers with fake interview tasks spreading malware

Security Affairs: Malicious npm and PyPI packages linked to Lazarus APT fake recruiter campaign

Hacker News: Lazarus Campaign Plants Malicious Packages in npm and PyPI Ecosystems

Help Net Security: Open-source attacks move through normal development workflows

CyberScoop: We moved fast and broke things. It’s time for a change

Security Boulevard - Report: Open Source Malware Instances Increased 73% in 2025

Venture Beat: Seven steps to AI supply chain visibility — before a breach forces the issue

Bleeping Computer: Malicious VSCode Marketplace extensions hid trojan in fake PNG file
