
1 min read


What Happened The Miasma worm s source code was deliberately distributed on GitHub through compromised developer accounts. Unlike accidental exposures or proof-of-concept leaks, this was a targeted at

On May 11, 2026, attackers published 84 malicious npm packages across 42 @tanstack repositories. Each package carried cryptographically valid SLSA Build Level 3 attestations. If your team relies on SL

What Happened Microsoft removed 73 GitHub repositories after malware compromised developer credentials and exposed a PyPI publishing token. The attack targeted the durabletask PyPI token, allowing an