SafeDep Headlines

Latest news and coverage for SafeDep

Filter by headline type:

Recent Headlines

30 headlines

Cybernoz

The ‘Miasma’ worm source code briefly leaked on GitHub

SafeDep reported the leak of Miasma worm source code on GitHub, analyzing its features including a dead-man switch and AI coding assistant poisoning.

Companies:SafeDep
Media MentionJun 11, 2026

LavX News

The 'Miasma' worm source code briefly leaked on GitHub, raising fears of copycat supply-chain attacks

Article reports SafeDep's discovery of the Miasma worm source code leak on GitHub, detailing its features and dead-man switch.

Companies:SafeDep
OSS News & ViewsJun 11, 2026

Data Today

Miasma worm: live coverage of the Red Hat npm attack | Data Today

Data Today's live coverage of the Miasma worm includes multiple references to Socket's research, campaign tracker, and detection of the PyPI wave.

Companies:SafeDepSocket
Media MentionJun 11, 2026

BleepingComputer

The ‘Miasma’ worm source code briefly leaked on GitHub

Researchers at SafeDep reported that the Miasma credential-stealing worm's source code was leaked on GitHub via compromised developer accounts, detailing its capabilities and implications.

Companies:SafeDep
Media MentionJun 10, 2026

The Register

Miasma supply-chain attack toolkit goes public on GitHub

The Register reports on the Miasma worm's source code being published on GitHub, citing SafeDep's analysis of the self-spreading malware.

Companies:SafeDep
Media MentionJun 9, 2026

ComplexDiscovery

When the worm targets the assistant: Miasma turns AI coding agents into the trigger

ComplexDiscovery discusses Miasma's use of AI coding agents, citing SafeDep's documentation of the campaign's source-repository compromises.

Companies:SafeDep
Media MentionJun 7, 2026

CPO Magazine

Megalodon Supply Chain Attack Infects Over 5,500 GitHub Repositories with Backdoors and Stealers

SafeDep detected the Megalodon supply chain attack that infected over 5,500 repositories and stole cloud credentials.

Companies:SafeDep
Media MentionJun 2, 2026

InfoSec Today

Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm

InfoSec Today covers the Miasma supply chain attack, referencing analyses from SafeDep and other security firms.

Companies:SafeDep
Media MentionJun 1, 2026

Yahoo Tech

GitHub hit with another major attack

SafeDep researchers uncovered the Megalodon campaign infecting over 5,500 GitHub repositories with an infostealer.

Companies:SafeDep
Media MentionMay 25, 2026

Mashable

Megalodon cyberattack infects 5,500 GitHub open-source repositories with malware, researchers say

SafeDep researchers detailed the Megalodon supply chain attack that infected over 5,500 GitHub repositories.

Companies:SafeDep
Media MentionMay 25, 2026

SecurityWeek

Over 5,500 GitHub Repositories Infected in 'Megalodon' Supply Chain Attack - SecurityWeek

SafeDep discovered the 'Megalodon' supply chain attack that infected over 5,500 GitHub repositories with malicious CI workflows to steal credentials.

Companies:SafeDep
OSS News & ViewsMay 25, 2026

ProbablyPwned

Megalodon Attack Backdoors 5,561 GitHub Repos in Six Hours | ProbablyPwned

SafeDep's Malysis scanning engine detected the Megalodon operation that backdoored thousands of repositories.

Companies:SafeDep
Media MentionMay 23, 2026

Ciphers Security

Megalodon: Supply Chain Attack Backdoors 5,561 GitHub Repos In Six Hours Via CI/CD Workflow Injection

Ciphers Security provides a detailed technical analysis of the Megalodon attack, crediting SafeDep for discovering the campaign and analyzing the payload.

Companies:SafeDep
Media MentionMay 23, 2026

CyberSecureFox

Mini Shai-Hulud Npm Attack Hits AntV Supply Chain

CyberSecureFox reports on the Mini Shai-Hulud attack affecting AntV packages, citing SafeDep's independent analysis of 631 malicious versions in 314 packages.

Companies:SafeDep
Media MentionMay 22, 2026

Cybernews

GitHub repos hijacked in massive Megalodon attack| Cybernews

Cybernews reports on the Megalodon attack, citing SafeDep's research and quoting their findings about workflow backdooring and credential theft.

Companies:SafeDep
Media MentionMay 22, 2026

Cloud Security Alliance

Shai-Hulud/Megalodon: A Two-Wave AI Developer Supply Chain Attack – Lab Space

CSA Lab Space publishes a research note analyzing the Shai-Hulud and Megalodon attacks, referencing SafeDep's discovery and analysis of the Megalodon wave.

OSS News & ViewsMay 22, 2026

Hackread

5,561 GitHub Repositories Hit by Megalodon Supply Chain Attack in Six Hours

Hackread reports on the Megalodon attack, detailing SafeDep's discovery and analysis of the campaign that targeted over 5,500 repositories.

Companies:SafeDep
Media MentionMay 22, 2026

IMP.NEWS

Hackers Push Hundreds of Malicious Open Source Package Updates - IMP.NEWS

IMP.NEWS covers the supply chain attack, citing SafeDep's finding that attackers published over 630 malicious versions across 317 packages in 20 minutes.

Companies:SafeDep
Media MentionMay 21, 2026

SafeDep

Mini Shai-Hulud Strikes Again: 317 npm Packages Compromised - Real-time Open Source Software Supply Chain Security

SafeDep reports a major supply chain attack where 317 npm packages were compromised in 22 minutes, with malware targeting credentials and AI coding tools.

Companies:SafeDep
AnnouncementMay 19, 2026

Tech Weekly

Hackers Target Numerous Popular Open Source Packages in Ongoing Supply Chain Attack - Tech Weekly

Tech Weekly reports on the supply chain attack, citing SafeDep's analysis that hackers released over 630 malicious versions across 317 packages.

Companies:SafeDep
Media MentionMay 19, 2026

The Register

Shai-Hulud keeps burrowing: 314 npm packages infected after another account compromise

The Register reports on the Mini Shai-Hulud attack where 314 npm packages were infected, citing SafeDep's analysis of the malware and its credential-stealing payload.

Companies:SafeDep
Media MentionMay 19, 2026

Yahoo Tech

Hackers have compromised dozens of popular open source packages in an ongoing supply chain attack

Yahoo Tech covers the wave of supply chain attacks, quoting SafeDep's findings about over 630 malicious versions across 317 packages published in 20 minutes.

Companies:SafeDep
Media MentionMay 19, 2026

BleepingComputer

Shai Hulud attack ships signed malicious TanStack, Mistral npm packages

Socket tracked 416 compromised package artifacts in the Shai Hulud attack.

Companies:SafeDepSocket
Media MentionMay 12, 2026

InfoWorld

Mistral AI SDK, TanStack Router hit in npm software supply chain attack

The article discusses a supply chain attack affecting npm packages, with SafeDep being one of the first to detect the compromise and providing analysis and action items.

Companies:SafeDep
Media MentionMay 12, 2026

VentureBeat

Protect your enterprise now from the Shai-Hulud worm and npm vulnerability in 6 actionable steps | VentureBeat

VentureBeat's analysis of the Shai-Hulud worm references SafeDep's confirmation of Mistral AI package compromise.

Companies:SafeDep
Media MentionMay 12, 2026

COSS Weekly Newsletter

Stay up to date with the latest news, funding rounds, and announcements from the COSS universe.

Check out COSS Weekly on the web

All information submitted through this form is handled in accordance with the Privacy Policy of Chinstrap Community.

or

Latest Content from Chinstrap Community

View all