Plugin4Shell Flaw Lets Repository Owners Swap Pinned Plugin Code in Claude Code, Codex, and Copilot
Security firm Air Security found a zero-click flaw letting a plugin repository owner bypass commit-hash pinning in four AI coding agents.
Signal
14 articles covering "open-source-security"
Security firm Air Security found a zero-click flaw letting a plugin repository owner bypass commit-hash pinning in four AI coding agents.
The Rust Security Response Team disclosed and patched a Miri flaw that stored all environment variables in target/, letting cached CI output expose secrets to pull requests.
OX Security found 24 npm packages built solely to let mirrors like unpkg serve fake Cloudflare CAPTCHA pages that can redirect to ClickFix-style phishing.
TrendAI found 14 npm packages disguised as calendar utilities quietly installing RedShell, a Linux implant tied to the AI-assisted RedC2 4.0 command-and-control framework.
Rust's security team removed a malicious proc-macro1 crate and the arrayref, internment, and append-only-vec crates it compromised, each pulled from crates.io within about 90 minutes.
Sonatype found six npm packages that decode malware C2 server IPs from Ethereum transaction bytes, using a technique tied to North Korea's Contagious Interview campaign.
Yeeth Security found 'Solidity Pro' VS Code extensions that evolved from a delayed Cloudflare-Worker dropper into a Telegram-based wallet and credential stealer targeting web3 developers.
Sonatype is tracking sonatype-2026-005660, a campaign that has published 846 malicious npm packages across throwaway accounts, dropping cross-platform malware with DNS-based fallback delivery.
A self-propagating worm hijacked keyv and related npm packages on August 4 after a maintainer's GitHub account was breached, spreading to 1,300+ package versions.
Attackers rewrote Git tags across four Laravel localization packages to point to malicious forks, poisoning hundreds of versions and deploying a credential stealer targeting cloud keys, SSH, and crypto wallets.
Attackers hijacked the primary Axios maintainer's npm account and published two malicious versions that installed a cross-platform remote access trojan, exposing one of the JavaScript ecosystem's most downloaded packages.
Attackers hijacked 75 of 76 version tags in the widely used trivy-action GitHub Action to steal CI/CD credentials, then deployed a self-propagating npm worm that uses the Internet Computer Protocol as an untakeable-down command-and-control channel.