Claude Opus commit added malicious npm dependency in Feb 2026, enabling crypto theft and persistent RAT access.
GlassWorm, a known malware, has put 73 harmful extensions into OpenVSX's registry. Hackers use it to steal developers' crypto ...
A hardcoded ClickUp API key exposed hundreds of corporate and government emails for over a year, raising new SaaS security ...