







Learn how attackers exploit automated bot traffic as part of software supply chain attacks to artificially inflate download counters and mask malicious payloads as legitimate.
keyv and cacheable npm Package Hijacked in Supply Chain Attack | Wiz Blog
Wiz Research is actively investigating an ongoing software supply chain attack affecting multiple keyv/cacheable npm packages.

The secure way to release an npm package in 2026—Martian Chronicles, Evil Martians’ team blog
How to protect your npm package from being stolen in a supply chain attack and improve its position in security ratings

Inside the keyv npm Supply Chain Compromise | Snyk
The keyv npm compromise used preinstall malware, trusted provenance, and IDE hooks to target developer and CI credentials. Learn how to detect and respond.

Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild
Uncover real-world indirect prompt injection attacks and learn how adversaries weaponize hidden web content to exploit LLMs for high-impact fraud.

Socket - Block zero-day supply chain attacks
Socket fights vulnerabilities and provides visibility, defense-in-depth, and proactive supply chain protection for JavaScript, Python, and Go dependen...

The Axios supply chain attack used individually targeted social engineering
The Axios team have published a full postmortem on the supply chain attack which resulted in a malware dependency going out in a release the other day, and it involved …
The Axios supply chain attack used individually targeted social engineering
The Axios team have published a full postmortem on the supply chain attack which resulted in a malware dependency going out in a release the other day, and it involved …
Keyv and friends compromised in npm supply chain attack
Mini Shai-Hulud malware was injected into keyv and eight related npm packages on August 4, 2026 after an attacker compromised the maintainer's GitHub account

npm Worm Poisons keyv, cacheable and 400+ Other Packages Across Twelve Organisations
A worm moved one byte-identical credential stealer through more than 400 npm packages in twelve organisations on 4 August 2026, including @ornikar, @deliveroo, @servicetitan, @qlik, Picsart and the keyv and cacheable family. latest still resolves to a poisoned version on most affected names, and the payload installs a dead-man switch that fires when the stolen GitHub token is revoked, so rotating credentials first triggers it.

Supply chain attack on arrayref | Rust Blog
Empowering everyone to build reliable and efficient software.

AI-driven Bot Attacks Surged 12.5x According to Thales Bad Bot Report
Bots now dominate the internet, accounting for over half of all traffic, with 40% classified as malicious.AI is erasing the line between legitimate and maliciou

An update on the scraper situation
Our article 'Fighting the AI scraper bot scourge', published in early 2025, discussed the probl [...]
IP Intelligence, Bot Detection, Fraud Detection | IPQS
Prevent fraud and detect bots confidently with IPQS fraud detection solutions including bot detection, proxy detection, & email validation. IPQS fraud prevention tools detect fraud, bad bots, high risk users, and fraudulent transactions.
Defeating Prompt Injections by Design
Large Language Models (LLMs) are increasingly deployed in agentic systems that interact with an untrusted environment. However, LLM agents are vulnerable to prompt injection attacks when handling untrusted data. In this paper we propose CaMeL, a robust defense that creates a protective system layer around the LLM, securing it even when underlying models are susceptible to attacks. To operate, CaMeL explicitly extracts the control and data flows from the (trusted) query; therefore, the untrusted data retrieved by the LLM can never impact the program flow. To further improve security, CaMeL uses a notion of a capability to prevent the exfiltration of private data over unauthorized data flows by enforcing security policies when tools are called. We demonstrate effectiveness of CaMeL by solving $77\%$ of tasks with provable security (compared to $84\%$ with an undefended system) in AgentDojo. We release CaMeL at https://github.com/google-research/camel-prompt-injection.

Getting Bots to Respect Boundaries
Getting Bots to Respect Boundaries How AI Crawlers Are Straining Web Infrastructure Audrey HingleJanuary 2026 Image by Janet Turra & Cambridge Diversity Fundbetterimagesofai.org creativecommons.org/licenses/by/4.0 Contents Introduction: Setting up the Problem 3 Understandin...
Hacker News: Honest Edition