Inside the npm Supply-Chain Attacks Targeting AI Coding Tools
The slopsquatting threat. An investigation into DPRK-linked npm attacks, AI hallucinated package names, and self-replicating worms compromising CI/CD pipelines.
8/1/202623 min read
2 articles tagged with Supply Chain Security
The slopsquatting threat. An investigation into DPRK-linked npm attacks, AI hallucinated package names, and self-replicating worms compromising CI/CD pipelines.
The AI extension threat landscape. How malicious VS Code extension typosquatting, poisoned MCP servers, `.cursorrules` injection, and rogue model proxies attack developers in 2026.