SafeDep Headlines
Latest news and coverage for SafeDep
Recent Headlines
30 headlinesCybernoz
The ‘Miasma’ worm source code briefly leaked on GitHub
SafeDep reported the leak of Miasma worm source code on GitHub, analyzing its features including a dead-man switch and AI coding assistant poisoning.
LavX News
The 'Miasma' worm source code briefly leaked on GitHub, raising fears of copycat supply-chain attacks
Article reports SafeDep's discovery of the Miasma worm source code leak on GitHub, detailing its features and dead-man switch.
Data Today
Miasma worm: live coverage of the Red Hat npm attack | Data Today
Data Today's live coverage of the Miasma worm includes multiple references to Socket's research, campaign tracker, and detection of the PyPI wave.
BleepingComputer
The ‘Miasma’ worm source code briefly leaked on GitHub
Researchers at SafeDep reported that the Miasma credential-stealing worm's source code was leaked on GitHub via compromised developer accounts, detailing its capabilities and implications.
The Register
Miasma supply-chain attack toolkit goes public on GitHub
The Register reports on the Miasma worm's source code being published on GitHub, citing SafeDep's analysis of the self-spreading malware.
ComplexDiscovery
When the worm targets the assistant: Miasma turns AI coding agents into the trigger
ComplexDiscovery discusses Miasma's use of AI coding agents, citing SafeDep's documentation of the campaign's source-repository compromises.
CPO Magazine
Megalodon Supply Chain Attack Infects Over 5,500 GitHub Repositories with Backdoors and Stealers
SafeDep detected the Megalodon supply chain attack that infected over 5,500 repositories and stole cloud credentials.
InfoSec Today
Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm
InfoSec Today covers the Miasma supply chain attack, referencing analyses from SafeDep and other security firms.
Yahoo Tech
GitHub hit with another major attack
SafeDep researchers uncovered the Megalodon campaign infecting over 5,500 GitHub repositories with an infostealer.
Mashable
Megalodon cyberattack infects 5,500 GitHub open-source repositories with malware, researchers say
SafeDep researchers detailed the Megalodon supply chain attack that infected over 5,500 GitHub repositories.
SecurityWeek
Over 5,500 GitHub Repositories Infected in 'Megalodon' Supply Chain Attack - SecurityWeek
SafeDep discovered the 'Megalodon' supply chain attack that infected over 5,500 GitHub repositories with malicious CI workflows to steal credentials.
ProbablyPwned
Megalodon Attack Backdoors 5,561 GitHub Repos in Six Hours | ProbablyPwned
SafeDep's Malysis scanning engine detected the Megalodon operation that backdoored thousands of repositories.
Ciphers Security
Megalodon: Supply Chain Attack Backdoors 5,561 GitHub Repos In Six Hours Via CI/CD Workflow Injection
Ciphers Security provides a detailed technical analysis of the Megalodon attack, crediting SafeDep for discovering the campaign and analyzing the payload.
CyberSecureFox
Mini Shai-Hulud Npm Attack Hits AntV Supply Chain
CyberSecureFox reports on the Mini Shai-Hulud attack affecting AntV packages, citing SafeDep's independent analysis of 631 malicious versions in 314 packages.
Cybernews
GitHub repos hijacked in massive Megalodon attack| Cybernews
Cybernews reports on the Megalodon attack, citing SafeDep's research and quoting their findings about workflow backdooring and credential theft.
Cloud Security Alliance
Shai-Hulud/Megalodon: A Two-Wave AI Developer Supply Chain Attack – Lab Space
CSA Lab Space publishes a research note analyzing the Shai-Hulud and Megalodon attacks, referencing SafeDep's discovery and analysis of the Megalodon wave.
Hackread
5,561 GitHub Repositories Hit by Megalodon Supply Chain Attack in Six Hours
Hackread reports on the Megalodon attack, detailing SafeDep's discovery and analysis of the campaign that targeted over 5,500 repositories.
IMP.NEWS
Hackers Push Hundreds of Malicious Open Source Package Updates - IMP.NEWS
IMP.NEWS covers the supply chain attack, citing SafeDep's finding that attackers published over 630 malicious versions across 317 packages in 20 minutes.
SafeDep
Mini Shai-Hulud Strikes Again: 317 npm Packages Compromised - Real-time Open Source Software Supply Chain Security
SafeDep reports a major supply chain attack where 317 npm packages were compromised in 22 minutes, with malware targeting credentials and AI coding tools.
Tech Weekly
Hackers Target Numerous Popular Open Source Packages in Ongoing Supply Chain Attack - Tech Weekly
Tech Weekly reports on the supply chain attack, citing SafeDep's analysis that hackers released over 630 malicious versions across 317 packages.
The Register
Shai-Hulud keeps burrowing: 314 npm packages infected after another account compromise
The Register reports on the Mini Shai-Hulud attack where 314 npm packages were infected, citing SafeDep's analysis of the malware and its credential-stealing payload.
Yahoo Tech
Hackers have compromised dozens of popular open source packages in an ongoing supply chain attack
Yahoo Tech covers the wave of supply chain attacks, quoting SafeDep's findings about over 630 malicious versions across 317 packages published in 20 minutes.
BleepingComputer
Shai Hulud attack ships signed malicious TanStack, Mistral npm packages
Socket tracked 416 compromised package artifacts in the Shai Hulud attack.
InfoWorld
Mistral AI SDK, TanStack Router hit in npm software supply chain attack
The article discusses a supply chain attack affecting npm packages, with SafeDep being one of the first to detect the compromise and providing analysis and action items.
VentureBeat
Protect your enterprise now from the Shai-Hulud worm and npm vulnerability in 6 actionable steps | VentureBeat
VentureBeat's analysis of the Shai-Hulud worm references SafeDep's confirmation of Mistral AI package compromise.
COSS Weekly Newsletter
Stay up to date with the latest news, funding rounds, and announcements from the COSS universe.
Check out COSS Weekly on the webLatest Content from Chinstrap Community
View allCOSS Weekly – Week of July 27, 2026
This week in COSS: On the funding front, Databricks raised $3 billion at a $188 billion valuation, e...
COSS Weekly – Week of July 20, 2026
This week in COSS: Nous Research, the startup behind the OSS Hermes agent, is in talks to raise mew ...
Battle of the Software Acronyms: BYOC Is Beating SaaS, but the Winner is COSS
On June 15, 2026, Ververica, a company founded by the original creators of the open source Apache Fl...
COSS Weekly – Week of July 13, 2026
This week in COSS: Ollama raises a $65M Series B, Bespoke Labs announces a $40M Seed and Series A, a...
COSS Weekly – Week of July 6, 2026
This week in COSS: Together AI announced an $800M Series C to accelerate the shift to open-source AI...
COSS Weekly – Week of June 29, 2026
This week in COSS: The acquisition trend continued as Qualcomm agreed to acquire Modular for nearly ...
COSS Weekly – Week of June 22, 2026
This week in COSS: Databricks reported annualized revenue of $6.9 billion — up over 80% year-over-ye...
COSS Weekly – Week of June 15, 2026
This week in COSS: The recent flurry of COSS M&A activity continues as VoidZero was acquired by Clou...

