Fake Stars Inflate Popularity of Malicious GitHub Repositories

https://arxiv.org/pdf/2412.13459 A new study reveals a significant problem with inauthentic “stars” being used to artificially inflate the popularity of scam and malware distribution repositories on GitHub. These fake stars mislead users into trusting...

Malicious NPM Packages and VSCode Extensions Target Developers

https://www.sonatype.com/blog/counterfeit-eslint-and-node-types-libraries-downloaded-thousands-of-times-abuse-pastebin Cybersecurity researchers have discovered a wave of malicious npm packages and Visual Studio Code (VSCode) extensions targeting developers. These...

Malicious VSCode Extensions Steal Developer Credentials

https://medium.com/@amitassaraf/vscode-extension-trivia-real-or-cake-f729adc9e03e Cybersecurity researchers have discovered a wave of malicious Visual Studio Code extensions designed to steal credentials from developers. These extensions, disguised as legitimate tools...