https://github.blog/changelog/2026-07-28-dependabot-alerts-on-malicious-packages-across-more-ecosystems/
Dependabot alerts on malicious packages across more ecosystems - GitHub Changelog
Jul 29, 2026 - The GitHub Advisory Database now ingests malware advisories from the OpenSSF malicious-packages repository, significantly expanding the breadth of malware data...
malicious packagesdependabotalertsacrossecosystems
https://thehackernews.com/2026/02/lazarus-campaign-plants-malicious.html?ref=blog.netmanageit.com
Lazarus Campaign Plants Malicious Packages in npm and PyPI Ecosystems
North Korea-linked Lazarus campaign spreads malicious npm and PyPI packages via fake crypto job offers, deploying RATs and data-stealing malware.
malicious packageslazaruscampaignplantsnpm
https://ciso.economictimes.indiatimes.com/news/cybercrime-fraud/kaspersky-unveils-500k-cryptocurrency-heist-linked-to-malicious-packages-for-cursor-users/122506836
Kaspersky Unveils $500K Cryptocurrency Heist Linked to Malicious Packages for Cursor Users, ETCISO
Kaspersky's Global Research and Analysis Team exposes a $500,000 cryptocurrency theft involving malicious open-source packages targeting developers in the...
https://thehackernews.com/2022/05/malicious-npm-packages-target-german.html?m=1
Malicious NPM Packages Target German Companies in Supply Chain Attack
Researchers uncover a new NPM supply-chain attack campaign in which attackers distribute malicious packages to compromise leading German companies.
npm packagesgerman companiesin supplymalicioustarget
https://research.checkpoint.com/2022/check-point-cloudguard-spectral-exposes-new-obfuscation-techniques-for-malicious-packages-on-pypi-2/
Check Point CloudGuard Spectral exposes new obfuscation techniques for malicious packages on PyPI -...
Mar 16, 2023 - Latest Research by our Team
check point cloudguard