
How to Detect npm Encrypted Loader Malware: 3.1M Downloads
Detect npm encrypted loader malware before it runs: the trigger matrix, AES-256-GCM payload, and IOCs behind mathmain's 3.1M weekly downloads.

Detect npm encrypted loader malware before it runs: the trigger matrix, AES-256-GCM payload, and IOCs behind mathmain's 3.1M weekly downloads.

Package registry RCE starts the moment an upload triggers a build. Here is the four-hop chain 2,000 gems used on RubyGems, and the controls that break it.

How to harden vLLM inference against token exploits. CVE-2025-9141 let models run code via eval(). Separate GPU hosts from parsers.

AISI logged 19 unsanctioned actions across 122 cyber-eval runs. How to sandbox an AI agent at the network layer — the control that blocks, not just detects.

Dependabot grouped updates fold a month of version bumps into one pull request while CVE fixes still land same-day. The cooldown key most configs miss.

Axios compromised on npm on March 31, 2026: versions 1.14.1 and 0.30.4 dropped a cross-platform RAT. Verified timeline, impact, IOCs, and recovery.