varunsharma07
- Karma
- 678
- Created
- 4 years ago
About
Founder of StepSecurity (https://www.stepsecurity.io)Recent Submissions
- 1. ▲ Multiple mastra NPM packages compromised (github.com)
- 2. ▲ Ongoing NPM supply chain attack uses binding.gyp to spread like a worm (github.com)
- 3. ▲ Laravel-Lang Supply Chain Attack (github.com)
- 4. ▲ NX VS Code extension compromised again (github.com)
- 5. ▲ Actions-cool/issues-helper GitHub Action Compromised (github.com)
- 6. ▲ Malicious node-IPC Versions Published to NPM (github.com)
- 7. ▲ Postmortem: TanStack NPM supply-chain compromise (tanstack.com)
- 8. ▲ Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push (stepsecurity.io)
- 9. ▲ Show HN: Scan your dev machine for AI agents, MCP servers, and IDE extensions (github.com)
- 10. ▲ Xygeni/xygeni-action GitHub Action is compromised – poisoned tag is still live (stepsecurity.io)