At least 15 malicious plugins in the JetBrains Marketplace were designed to steal AI API keys from developers and gain access to internal corporate services.
Miasma replicates autonomously across Git repositories and automatically deletes user data when its GitHub token is blocked, with the now-public source code expected to lead to further variants.
Bright Data integrates an SDK into free apps that repurposes smart TVs and smartphones as exit nodes for a global proxy network with 400 million IP addresses without sufficient transparency—even when VPN connections are active.
Over 400 Arch Linux AUR packages were compromised with infostealer malware, posing a data exfiltration risk to all systems that installed these packages on or after June 11, 2026.
Publicly available supply-chain attack kits, commercialized RAT infrastructures, and empirically demonstrated phishing vulnerability of AI agents mark a professionalization of the threat landscape.
A self-replicating worm compromises 73 Microsoft repositories through stolen administrative credentials, exploiting the trust model of GitHub and npm without leveraging software vulnerabilities.
Attackers operate highly ranked fake pages for tools like Ghidra and dnSpy on Google, redirect users through TDS-controlled JavaScript to malware servers, and evade security analysis by filtering VPNs, data centers, and repeated access.
Microsoft restored some GitHub repos after 73 open-source projects were compromised with information-stealer malware, while keeping others offline as the security investigation continues.
A locally hosted open-source language model enables a malware prototype to perform independent reasoning, network exploration, and replication without external AI APIs.