Secure how AI behaves, not just what it’s built from.
Cut through the noise to reduce real application risk.
Automated dependency updates, running on millions of repos.
Extend Mend AppSec to running apps, APIs, and aging dependencies.
Mini Shai-Hulud hits openapi-react-query-codegen: 10 malicious npm versions
An npm supply chain attack published ten malicious versions
Mini Shai-Hulud Hits keyv: Trojanized Release Exfiltrates CI Secrets via GitHub
Trojanized keyv@6.0.0 exfiltrates CI secrets through GitHub’s own API.
Mastra npm Scope Takeover: 140+ Packages Compromised via easy-day-js Dropper
@Mastra npm: 140+ Packages Compromised
Miasma: Red Hat Cloud Services npm Packages Hit by a Mini Shai-Hulud-Style Campaign
npm packages in @redhat-cloud-services drop a multi-stage cloud credential stealer.
Laravel-Lang Composer tag-rewrite Supply Chain Attack
Four Laravel-Lang Composer packages were poisoned via tag rewrite.
Mini Shai-Hulud Hits @antv: 323 npm Packages Compromised Through the atool Maintainer Account
Mini Shai-Hulud strikes again: 323 npm packages compromised via @antv’s atool.
Join our subscriber list to get the latest news and updates
Thanks for signing up!ย