129
3
Show HN: PMG, open source package firewall (github.com/safedep)
2
Jscrambler 8.14.0 Compromised with Credential Stealer (safedep.io)
4
Claude Mythos and Cybersecurity (schneier.com)
1
Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit (cloud.google.com)
1
Step by Step Analysis of Malicious NPM Package (safedep.io)
1
OpenClaw bot calls out maintainer when its PR got rejected (crabby-rathbun.github.io)
1
Show HN: Gryph – Audit Trail for AI Coding Agents (Claude Code, Cursor, Gemini) (github.com/safedep)
2
Agent Skills Threat Model (safedep.io)
2
Catching malicious package releases using a transparency log (trailofbits.com)
1
CVE-2025-66491: Traefik's "Verify=on" Turned TLS Off (aisle.com)
2
DarkGPT: Malicious Visual Studio Code Extension Targeting Developers (safedep.io)
1
Exposing and Exploiting Incomplete Branch Predictor Isolation in Cloud (ethz.ch)
1
KnownSec breach: What we know so far (substack.com)
2
Buying browser extensions for fun and profit (secureannex.com)
2
Curious Case of Embedded Executable in a Newly Introduced Transitive Dependency (safedep.io)
2
NPM Supply Chain Malware with Self-Replicating Behaviour (safedep.io)
1
Tensorflow.js Typosquatting Attack: Malicious Package Targeting AI/ML Developers (safedep.io)
1
Secure Vibe Coding with AI Agents (safedep.io)
1
ESLint-config-prettier: How NPM Package with 30M Downloads Spread Malware (safedep.io)
1
Scavenger Malware Distributed via ESLint-Config-Prettier NPM Package Hack (invokere.com)
2
Near Real-Time Stream of Open Source Packages Published to Public Registries (vetpkg.dev)
5
Critical RCE Vulnerability in Anthropic MCP Inspector – CVE-2025-49596 (oligo.security)
2
Ask HN: HN: Why do we code review?
1
The PostgreSQL Locking Trap That Killed Our Production API (and How We Fixed It) (root.sigsegv.in)
2
Show HN: Xbom – Generate AI and SaaS-Aware SBOMs from Code Using Static Analysis (github.com/safedep)
1
Vet MCP: Software Composition Analysis for AI Code Editors (github.com/safedep)
1
Catching the Silent Threat: How Dynamic Analysis Revealed an NPM Attack Chain (safedep.io)
1
Kubernetes Limits Links to Third Party Projects (github.com/kubernetes)
4
Show HN: Vibe Coded GitHub PR Bot for Integrating a GitHub Action (vetpkg.dev)
3
Sneaky Malware Hidden in Transitive Dependency of ESLint-config-Airbnb-compat (root.sigsegv.in)
6
PMG: Wraps Package Managers to Prevent Installation of Malicious OSS Packages (github.com/safedep)
2
Why Build Software Frameworks (root.sigsegv.in)
1
AI Agents Are Here. So Are the Threats (paloaltonetworks.com)
6
Dynamic Malware Analysis of Open Source Packages at Scale (safedep.io)
2
DeepWiki Generated Technical Documentation for My OSS Security Project (deepwiki.com)
1
Verizon 2025 Data Breach Investigations Report [pdf] (verizon.com)
1
LLMs with the Model Context Protocol Allow Major Security Exploits (arxiv.org)
3
Detecting Malicious Source Code in PyPI Packages with LLMs (arxiv.org)
1
Analysing 5000 Malicious Open Source Packages (safedep.io)
1
Show HN: MCP Server Built in Go for Pinning GitHub Actions (github.com/safedep)
1
Show HN: Scan GitHub Actions for Malicious Code (github.com/safedep)
2
Typosquatt alert Malicious NPM Package: NYC-config (safedep.io)
1
Show HN: Eliminating Vulnerability False Positives Through Code Analysis (safedep.io)
1
Show HN: Vetpkg.dev – open-source Package Security Dashboard (vetpkg.dev)
1
What Is Next Generation Software Composition Analysis? (safedep.io)
1
Show HN: vet – Adding Support for Open Source Package Malware Scanning (github.com/safedep)
1
Malicious NPM Packages Using Burp Collaborator for Dependency Confusion Attack (safedep.io)
3
Show HN: Vet – Open-Source Software Supply Chain Security Tool (github.com/safedep)
1
Why Open Source Risks Are Larger Than Only Software Composition Analysis (safedep.io)
2
Lockfiles are an attack vector for introducing malware in software supply chain (safedep.substack.com)
1
Show HN: Vet now supports detecting malicious packages (github.com/safedep)
2
Show HN: I built a tool for policy driven vetting of open source packages (github.com/safedep)
1