Python 12
- CanisterWorm: npm Publisher Compromise Deploys Backdoor Across 29+ Packages
- PyPI Package Impersonates SymPy to Deliver Cryptomining Malware
- Surveillance Malware Hidden in npm and PyPI Packages Targets Developers with Keyloggers, Webcam Capture, and Credential Theft
- 2025 Blockchain and Cryptocurrency Threat Report: Malware in the Open Source Supply Chain
- Monkey-Patched PyPI Packages Use Transitive Dependencies to Steal Solana Private Keys
- The Landscape of Malicious Open Source Packages: 2025 Mid‑Year Threat Report
- The Bad Seeds: Malicious npm and PyPI Packages Pose as Developer Tools to Steal Wallet Credentials
- Black Basta's Dependency Confusion Ambitions and Ransomware in Open Source Ecosystems
- Malicious PyPI Package Exploits Deezer API for Coordinated Music Piracy
- Weaponizing OAST: How Malicious Packages Exploit npm, PyPI, and RubyGems for Data Exfiltration and Recon
- Noxia: Emerging Dark Web Hosting Provider Targets Python, Node.js, Go, and Rust Ecosystems
- Typosquatting on PyPI: Malicious Package Mimics Popular 'browser-cookie3' Library to Steal Sensitive Data