SafeDep Headlines

Latest news and coverage for SafeDep

Filter by headline type:

Recent Headlines

23 headlines

CPO Magazine

Megalodon Supply Chain Attack Infects Over 5,500 GitHub Repositories with Backdoors and Stealers

SafeDep detected the Megalodon supply chain attack that infected over 5,500 repositories and stole cloud credentials.

Companies:SafeDep
Media MentionJun 2, 2026

Yahoo Tech

GitHub hit with another major attack

SafeDep researchers uncovered the Megalodon campaign infecting over 5,500 GitHub repositories with an infostealer.

Companies:SafeDep
Media MentionMay 25, 2026

Mashable

Megalodon cyberattack infects 5,500 GitHub open-source repositories with malware, researchers say

SafeDep researchers detailed the Megalodon supply chain attack that infected over 5,500 GitHub repositories.

Companies:SafeDep
Media MentionMay 25, 2026

SecurityWeek

Over 5,500 GitHub Repositories Infected in 'Megalodon' Supply Chain Attack - SecurityWeek

SafeDep discovered the 'Megalodon' supply chain attack that infected over 5,500 GitHub repositories with malicious CI workflows to steal credentials.

Companies:SafeDep
OSS News & ViewsMay 25, 2026

ProbablyPwned

Megalodon Attack Backdoors 5,561 GitHub Repos in Six Hours | ProbablyPwned

SafeDep's Malysis scanning engine detected the Megalodon operation that backdoored thousands of repositories.

Companies:SafeDep
Media MentionMay 23, 2026

Ciphers Security

Megalodon: Supply Chain Attack Backdoors 5,561 GitHub Repos In Six Hours Via CI/CD Workflow Injection

Ciphers Security provides a detailed technical analysis of the Megalodon attack, crediting SafeDep for discovering the campaign and analyzing the payload.

Companies:SafeDep
Media MentionMay 23, 2026

CyberSecureFox

Mini Shai-Hulud Npm Attack Hits AntV Supply Chain

CyberSecureFox reports on the Mini Shai-Hulud attack affecting AntV packages, citing SafeDep's independent analysis of 631 malicious versions in 314 packages.

Companies:SafeDep
Media MentionMay 22, 2026

Cybernews

GitHub repos hijacked in massive Megalodon attack| Cybernews

Cybernews reports on the Megalodon attack, citing SafeDep's research and quoting their findings about workflow backdooring and credential theft.

Companies:SafeDep
Media MentionMay 22, 2026

Cloud Security Alliance

Shai-Hulud/Megalodon: A Two-Wave AI Developer Supply Chain Attack – Lab Space

CSA Lab Space publishes a research note analyzing the Shai-Hulud and Megalodon attacks, referencing SafeDep's discovery and analysis of the Megalodon wave.

OSS News & ViewsMay 22, 2026

Hackread

5,561 GitHub Repositories Hit by Megalodon Supply Chain Attack in Six Hours

Hackread reports on the Megalodon attack, detailing SafeDep's discovery and analysis of the campaign that targeted over 5,500 repositories.

Companies:SafeDep
Media MentionMay 22, 2026

IMP.NEWS

Hackers Push Hundreds of Malicious Open Source Package Updates - IMP.NEWS

IMP.NEWS covers the supply chain attack, citing SafeDep's finding that attackers published over 630 malicious versions across 317 packages in 20 minutes.

Companies:SafeDep
Media MentionMay 21, 2026

SafeDep

Mini Shai-Hulud Strikes Again: 317 npm Packages Compromised - Real-time Open Source Software Supply Chain Security

SafeDep reports a major supply chain attack where 317 npm packages were compromised in 22 minutes, with malware targeting credentials and AI coding tools.

Companies:SafeDep
AnnouncementMay 19, 2026

Tech Weekly

Hackers Target Numerous Popular Open Source Packages in Ongoing Supply Chain Attack - Tech Weekly

Tech Weekly reports on the supply chain attack, citing SafeDep's analysis that hackers released over 630 malicious versions across 317 packages.

Companies:SafeDep
Media MentionMay 19, 2026

The Register

Shai-Hulud keeps burrowing: 314 npm packages infected after another account compromise

The Register reports on the Mini Shai-Hulud attack where 314 npm packages were infected, citing SafeDep's analysis of the malware and its credential-stealing payload.

Companies:SafeDep
Media MentionMay 19, 2026

Yahoo Tech

Hackers have compromised dozens of popular open source packages in an ongoing supply chain attack

Yahoo Tech covers the wave of supply chain attacks, quoting SafeDep's findings about over 630 malicious versions across 317 packages published in 20 minutes.

Companies:SafeDep
Media MentionMay 19, 2026

BleepingComputer

Shai Hulud attack ships signed malicious TanStack, Mistral npm packages

Socket tracked 416 compromised package artifacts in the Shai Hulud attack.

Companies:SafeDepSocket
Media MentionMay 12, 2026

InfoWorld

Mistral AI SDK, TanStack Router hit in npm software supply chain attack

The article discusses a supply chain attack affecting npm packages, with SafeDep being one of the first to detect the compromise and providing analysis and action items.

Companies:SafeDep
Media MentionMay 12, 2026

VentureBeat

Protect your enterprise now from the Shai-Hulud worm and npm vulnerability in 6 actionable steps | VentureBeat

VentureBeat's analysis of the Shai-Hulud worm references SafeDep's confirmation of Mistral AI package compromise.

Companies:SafeDep
Media MentionMay 12, 2026

InfoWorld

SAP npm package attack highlights risks in developer tools and CI/CD pipelines | InfoWorld

InfoWorld article lists SafeDep among researchers analyzing the SAP npm package attack.

Companies:SafeDep
Media MentionApr 30, 2026

SafeDep

Malicious redeem-onchain-sdk npm Targets Crypto Wallets - SafeDep

SafeDep analyzes a malicious npm package targeting crypto wallets, detailing its credential theft mechanisms and C2 infrastructure.

Companies:SafeDep
AnnouncementApr 29, 2026

SafeDep

Mini Shai Hulud and SAP Compromise - SafeDep

SafeDep reports on a supply chain attack compromising SAP npm packages, detailing the infection chain, credential theft, and indicators of compromise.

Companies:SafeDep
AnnouncementApr 29, 2026

SafeDep Blog

Malicious npm Package react-refresh-update Drops Cross-Platform Trojan on Developer Machines

SafeDep identified a malicious npm package impersonating `react-refresh` with 42 million weekly downloads. The package contained a two-layer obfuscated, multi-platform trojan dropper that runs silently on `require()`.

Companies:SafeDep
OSS News & ViewsMar 16, 2026

Help Net Security

VET: Open source software supply chain security tool

The article from Help Net Security mentions VET: Open source software supply chain security tool. It likely covers aspects related to the company's activities or impact.

Companies:SafeDep
Media MentionJun 3, 2025

COSS Weekly Newsletter

Stay up to date with the latest news, funding rounds, and announcements from the COSS universe.

Check out COSS Weekly on the web

All information submitted through this form is handled in accordance with the Privacy Policy of Chinstrap Community.

Latest Content from Chinstrap Community

View all