TensorFlow.js Typosquatting Attack: Malicious Package Targeting AI/ML Developers

1 min read Original article ↗

9 min read

Table of Contents

  • npm
  • oss
  • malware
  • tensorflow

Author

SafeDep Logo

Share

The Latest from SafeDep blogs

Follow for the latest updates and insights on open source security & engineering

The State of MCP Registries

The State of MCP Registries

Explore the architecture of the Model Context Protocol (MCP) and the state of its official registry. Learn how to consume server packages programmatically and discover the underlying challenges of...

Agent Skills Threat Model

Agent Skills Threat Model

Discover critical security threats in Agent Skills - Anthropic's open format for AI agent capabilities. Learn about supply chain attacks, deferred code execution, prompt injection, and multiple...

Background

SafeDep Logo

Ship Code

Not Malware

Install the SafeDep GitHub App to keep malicious packages out of your repos.

GitHub Install GitHub App