From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet
A poisoned npm package infected 140+ projects with a hidden payload. This report highlights how to detect, hunt, and defend ...
Ky 2.0 is an open-source JavaScript HTTP client built on the Fetch API, featuring significant updates such as consolidated ...
This repository is a collection of reference implementations for the Model Context Protocol (MCP), as well as references to community-built servers and additional resources. Important If you are ...
Ongoing research into AI agent framework security identified an exploit chain in AutoGen Studio (AutoGen’s open-source prototyping user interface) that allows untrusted web content rendered by a ...
claude-connect - Connect Claude to Clawdbot instantly and keep clauditor - Tamper-resistant audit watchdog for Clawdbot agents. claw-face - Floating avatar widget for AI agents showing emotions, ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results