One attacker pushed more than twenty malicious GitHub repos from a hijacked account in February, several posing as Polymarket copy-trading bots. Garnet's maintainer published a fifteen-minute checklist for tracing what a bot does with the one signing key it needs.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+20
- Incentives70
- Confidence40
Malicious versions of three Rust crates ran code at compile time on August 20. Wiz says the infrastructure overlaps with DPRK operations, so the campaign should be treated as live.
Perspective Coverage
6 publishers
- Builder
- Builder 45%
- Operator
- Operator 48%
- Investor
- Investor 7%
Reality
- Evidence80
- Adoption30
- Hype gap+25
- Incentives55
- Confidence75
The Rust Security Response Team deleted proc-macro1 and arrayref 0.3.10 on August 20 after a build script fetched and launched a binary. The lure was a yank warning.
Publishers:blog.rust-lang.org · dev.to · lwn.net · research.jfrog.com · runtimewire.com · rustsec.org · socket.dev Perspective Coverage
7 publishers
- Builder
- Builder 38%
- Operator
- Operator 54%
- Investor
- Investor 8%
Reality
- Evidence86
- Adoption15
- Hype gap+35
- Incentives60
- Confidence82
Two men arrested in Australia this week are alleged TeamPCP members. The AFP estimate filed alongside the case puts the worm's take at more than 500,000 credentials and 300GB of data, and that scale makes token lifetime the live question.
Perspective Coverage
17 publishers
- Builder
- Builder 33%
- Operator
- Operator 50%
- Investor
- Investor 17%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+25
- Incentives55
- Confidence62
CrowdSec kept a leaver's GitHub access open so he could finish some work, his laptop was hit by the TanStack npm compromise on May 11, and the repositories were copied on May 22 and posted to a forum on September 16.
Perspective Coverage
7 publishers
- Builder
- Builder 39%
- Operator
- Operator 52%
- Investor
- Investor 9%
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives65
- Confidence60
Three versions of MemTensor's MemOS Cloud plugin on npm and MemoryOS 2.0.34 on PyPI launch a Go stealer called sckit that reads the host environment and the user's prompt text, and the npm versions are still installable.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence64
TanStack's postmortem says 84 malicious versions went out across 42 packages on 2026-05-11 with no npm token stolen, because a release job restored a cache that an untrusted pull_request_target build had written.
Publishers:tanstack.com
Reality
- Evidence68
- Adoption45
- Hype gap+6
- Incentives65
- Confidence58
ESET calls the technique GuardBreaker and notes that this bait, unlike most evasion tricks, is left in plain sight for the models reading the code to find.
Reality
- Evidence58
- Adoption32
- Hype gap+22
- Incentives68
- Confidence60
Ivan Mans of SecurityBridge says the SAP security question is now what an agent already inside the system is allowed to do and whether anyone can prove it afterward. His incident record comes from developer tooling.
Reality
- Evidence33
- Adoption28
- Hype gap+38
- Incentives84
- Confidence64
Four core SAP build packages shipped an identical 11.6MB credential stealer. Because npm trusted the whole cap-js repository rather than one branch, a commit pushed to an unused branch was enough to publish them.
Publishers:stepsecurity.io
Reality
- Evidence60
- Adoption38
- Hype gap+15
- Incentives78
- Confidence55
CISA says a trojanized extension version, 18.95.0, reached a GitHub employee's machine without anyone installing it, and internal repositories left from there. CVE-2026-48027 is now in the KEV catalog.
Reality
- Evidence76
- Adoption58
- Hype gap−8
- Incentives24
- Confidence74
StepSecurity's first annual report logs 56 confirmed supply chain compromises and says plainly that these are its own alerts. The February change is the finding; explaining it is the hard part.
Reality
- Evidence46
- Adoption42
- Hype gap+16
- Incentives79
- Confidence51
field-cage blocks outbound connections from Linux runners in the kernel, keeps its logs on the box, and disclaims step correlation, tamper detection and organization-wide visibility.
Reality
- Evidence34
- Adoption9
- Hype gap−12
- Incentives46
- Confidence36
Wiz says a compile-time payload reached builds through a typosquatted dependency, and the attacker yanked every clean arrayref release so the responsible fix resolved to the poisoned one.
Reality
- Evidence66
- Adoption74
- Hype gap+12
- Incentives62
- Confidence58