open source security
(5 articles)May 12, 2026
RubyGems Suspends Signups After Malicious Packages
RubyGems suspended new account signups after hundreds of malicious packages flooded the registry. Here's what Ruby developers need to know right now.

April 29, 2026
SAP npm Packages Hit in Credential-Stealing Attack
Malicious SAP-related npm packages were caught stealing credentials in a supply chain attack. Here's what developers need to check right now.

April 29, 2026
DPRK npm Malware: AI-Powered RAT Attacks Hit Devs
North Korean hackers are planting AI-generated malware in npm packages via fake firms and RATs. Here's what developers need to know to stay safe.

April 23, 2026
Bitwarden CLI Hit by Checkmarx Supply Chain Attack
The Bitwarden CLI is being targeted in an active Checkmarx supply chain campaign. Learn what's at risk and how to protect your build pipeline now.

April 22, 2026
npm Supply Chain Worm Steals Developer Tokens
A self-propagating worm is hijacking npm packages to steal developer tokens. Learn how it spreads and what you can do to protect your projects now.