Bundler
-
Malvertising campaign assembles Windows malware inside victims’ browsers
A malvertising campaign dubbed SourTrade is using browsers to assemble Windows malware from pieces, with Confiant saying the operation has targeted traders and crypto investors in 12 countries since late 2024.
-
Malicious PyPI packages tied to Hades attack wave, researchers say
Researchers said a new Hades supply chain campaign poisoned 37 wheel artifacts across 19 PyPI packages, using startup hooks to run Bun-based malware that sought cloud, repository and developer credentials.
-
VS Code adds 2 hour delay for extension auto updates
Microsoft has added a two hour delay before Visual Studio Code auto updates most extensions, a move aimed at limiting supply chain risk. Trusted publishers are exempt, and users can still update manually.



