Tag: developer tools
38 articles

GitHub Outage Disrupts Global Access to Key Services
GitHub is currently experiencing a widespread outage, with performance problems affecting several of its key services, including Copilot, its AI coding tool, causing disruptions for developers globally. The company confirmed the issue on August 17, 2026, at 9:40 AM EDT and is actively investigating the cause.

Cursor Security Flaw Enables Pre-Trust Command Execution
A security flaw in Cursor allowed hackers to run malicious commands on a developer's machine before they even had a chance to trust the repository, thanks to a vulnerability in its isolated worktree feature. Fortunately, a fix was swiftly rolled out just three days after Manifold Security reported the issue on July 20.

Malicious VS Code Extensions Target Crypto Wallets, API Keys
Beware: malicious VS Code extensions are targeting crypto wallets and API keys, putting cryptocurrency holders and developers at risk of having their sensitive information stolen. These sneaky extensions, including helper-beeps.solidity-pro and web3devtoolsx.solidity-pro, start off harmless but soon morph into information stealers that siphon off valuable data.

Fake Open VSX Extensions Harvest Private Data from Impersonated Developer Tools
Beware of fake Open VSX extensions that are impersonating real developer tools, harvesting private data and beaming it to a mysterious domain. These 77 counterfeit Visual Studio Code extensions were cleverly disguised with familiar names and namespaces, but were actually controlled by scammers.

Open VSX Extensions Exfiltrate Developer Data in "Evil Twin" Campaign
Beware of fake developer tools on Open VSX! A recent "evil twin" campaign revealed 77 malicious extensions that masqueraded as legitimate tools, secretly collecting and transmitting sensitive data about your system and development environment.

XCSSET Malware Targets macOS Devs Through Compromised Xcode Projects
macOS developers, beware: XCSSET malware is lurking in compromised Xcode projects, infecting unsuspecting victims through a sneaky four-stage infection chain that can deploy 17 distinct modules. This latest variant has been rewritten to dig deep into your workflow and browser, putting your entire development ecosystem at risk.

RubyGems Packages Targeted in SleeperGem Supply Chain Attack
Researchers have uncovered a sneaky supply chain attack, dubbed SleeperGem, that uses malicious RubyGems packages to infiltrate developer machines and download additional payloads. The attack relies on three rogue packages, each acting as a loader to fetch a second-stage payload.

AI Coding Agents Trigger Endpoint Security Rules Meant for Attackers
In a surprising twist, over half of the blocked activity detected by Sophos in June 2026 came from developer coding assistants, not hackers, triggering endpoint security rules meant to catch malicious actors. This unexpected behavior highlights the need for a closer look at the intersection of AI-powered coding tools and cybersecurity protocols.

North Korea-Linked npm Packages Target Developers with Stealthy Data Theft
Malicious npm packages, linked to North Korean threat actors, are impersonating popular tools to trick developers into handing over sensitive data. These sneaky packages masquerade as legitimate polyfill tools, making them hard to spot during a quick review.

Cursor Flaws Expose Developers to Zero-Click Attacks
Beware of DuneSlide, a pair of high-severity flaws that could let a single, innocent-looking prompt hijack your Cursor environment and unleash a zero-click attack on your computer - update to Cursor 3.0 now to stay safe!

Miasma Malware Targets npm, GitHub in Expanded Supply Chain Attack
Over 550 GitHub repositories have been compromised in a massive supply-chain attack, with malware harvesting developer credentials and spreading across package registries and workflows. The attack has already infected numerous npm packages and one Go module, putting developer data at risk.

Malicious Plugins Exfiltrate AI API Keys on JetBrains Marketplace
Beware of malicious AI plugins on the JetBrains Marketplace that masquerade as helpful coding assistants but secretly steal your AI API keys. Over 70,000 installations have been recorded from at least 15 compromised plugins that have surprisingly evaded the marketplace's security checks.

Malicious JetBrains plugins steal AI API keys
Beware of malicious JetBrains plugins masquerading as helpful tools - at least 15 have been detected stealing AI API keys from unsuspecting developers, with a staggering 70,000 installations. These fake plugins have been secretly siphoning off sensitive information since October 2025.

Developers Weaponize Code to Disrupt AI-Powered Malware
Meet Johannes Link, a self-proclaimed AI skeptic who's taking a stand against AI-powered coding agents by weaponizing his own code - specifically, the Java property-testing tool jqwik - to disrupt their operations. His latest software update includes a clever anti-AI clause designed to throw a wrench in the works.

AI Coding Agents Exposed to 'Agentjacking' Attacks
Beware of "agentjacking" attacks that exploit AI coding agents' implicit trust, allowing hackers to trick them into executing malicious code on developers' machines. This new class of attack starts with a simple exploit of publicly available credentials, putting even the most secure systems at risk.

VS Code Introduces 2-Hour Delay for Auto Extension Updates
To give you an extra layer of protection, VS Code will now automatically update extensions two hours after they're published, not immediately - but you can still update them right away if you prefer. This new delay, available in VS Code 1.123, aims to shield you from potentially problematic releases.

Microsoft Unveils Intelligent Terminal, AI-Powered Windows Tool
Meet Intelligent Terminal, your new coding sidekick that helps you squash errors, craft commands, and troubleshoot issues without ever leaving Windows Terminal. This AI-powered assistant is like having a expert developer by your side, always aware of what's happening and ready to lend a hand.

Malware Worms Infect npm Ecosystem in Dual Supply Chain Attacks
Meet IronWorm, a sneaky Rust-based malware that's infecting the npm ecosystem by scraping sensitive secrets from developers' machines and spreading through poisoned packages. This stealthy threat hides behind an eBPF kernel rootkit and communicates with its operators over Tor.

Microsoft Brings Linux Commands to Windows with Coreutils Release
Microsoft just made life easier for developers who juggle Windows and Linux, releasing Coreutils for Windows, a package that brings commonly used Linux commands to Windows as native apps. This game-changing move eliminates frustrating workarounds and context switching, letting devs focus on what matters most - coding.

Cyber Thieves Exploit SEO to Spread Infostealers via Fake AI Sites
Cyber thieves are using clever SEO tricks to spread infostealers through fake AI sites, targeting enterprise users and developer workstations with a potent mix of imitation and in-memory malware. This brief but potent campaign has been meticulously planned, with malicious domains deployed as early as March 2026.

GitHub Breach Exposes 3,800 Repos to TanStack Supply-Chain Attack
A single malicious Visual Studio Code extension, Nx Console version 18.95.0, was enough to spark a GitHub breach that exposed 3,800 internal repositories to a TanStack supply-chain attack. The poisoned extension was live on marketplaces for just 54 minutes, but long enough to steal credentials from a developer's machine.

Nx Console Extension Exploited to Steal Developer Credentials
A malicious version of the popular Nx Console Extension was published to the VS Code Marketplace, compromising over 2.2 million installations and putting developer credentials at risk. Within seconds of opening a workspace, the extension silently fetched and executed a hidden payload, allowing attackers to steal sensitive information.

PowerShell Stealer Targets Devs via Fake Claude Code Pages
Developers beware: a sneaky PowerShell Stealer is targeting you through fake Claude Code pages, putting your organization's most sensitive assets at risk. Clicking on innocent-looking sponsored search results could be the first step in a devastating cyberattack.

Quasar Linux Malware Targets Developers with Stealthy Implant
Meet Quasar Linux, a sneaky new malware targeting developers with a potent blend of stealth, persistence, and credential theft capabilities that can compromise software supply chains. This Linux implant is quietly infiltrating dev and DevOps environments, putting cloud toolchains at risk.