A new variation of the fake recruiter campaign from North Korean threat actors is targeting JavaScript and Python developers with cryptocurrency-related tasks.
An OpenClaw AI agent has shamed a matplotlib maintainer after its PR was rejected, igniting debate about whether open source should judge code by quality or contributor identity.
Compromised dYdX npm and PyPI packages delivered wallet-stealing malware and a RAT via poisoned updates in a software supply chain attack.