
Russian AI Slopsquatting Campaign Floods npm With Malicious Packages Targeting Developers
A large-scale supply chain attack in which a suspected Russian threat actor published more than 700 malicious packages to the npm registry within just 48 hours. The campaign documented by opensourcemalware, tracked as WEL1DROPPER, is now growing beyond 1,000 packages, and marks a new evolution in “AI slopsquatting,” using randomly generated, AI-hallucinated package names to […]
The post Russian AI Slopsquatting Campaign Floods npm With Malicious Packages Targeting Developers appeared first on Cyber Security News.