VS Code Tasks supply chain attack needs new checks
VS Code Tasks supply chain attack is a package hijack pattern that can run outside npm lifecycle scripts, so scan editor configs now.
4 stories tagged npm.
VS Code Tasks supply chain attack is a package hijack pattern that can run outside npm lifecycle scripts, so scan editor configs now.
Mastra npm supply chain attack exposed AI build pipelines through more than 140 packages, so treat installs as secret exposure events.
Miasma is a self-propagating npm worm. It hijacked Red Hat's GitHub Actions OIDC trusted publishing to ship 96 backdoored @redhat-cloud-services versions whose preinstall hook runs a Bun credential stealer that then spreads with the secrets it steals.
TeamPCP is the cybercrime crew behind the Shai-Hulud npm worm. It open-sourced the malware in May 2026, then poisoned Red Hat's packages and blurred the question of who to blame.