⤷ Title: Hidden Protestware Found in 28+ npm Packages: Silently Targeting Russian Users
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 17 Jul 2025 00:06:14 +0000
════════════════════════
⌗ Tags: #Malware #Cyber_activism #cybersecurity #javascript #npm #open_source #Protestware #russia #supply chain attack #Ukraine
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 17 Jul 2025 00:06:14 +0000
════════════════════════
⌗ Tags: #Malware #Cyber_activism #cybersecurity #javascript #npm #open_source #Protestware #russia #supply chain attack #Ukraine
Daily CyberSecurity
Hidden Protestware Found in 28+ npm Packages: Silently Targeting Russian Users
Socket researchers uncovered widespread "protestware" in 28+ npm packages, silently disabling mouse interactions and playing the Ukrainian anthem for Russian-language users.
⤷ Title: The Sabotage of Automation: Open-Source Project jqwik Poisoned Against AI Agents
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 31 May 2026 10:08:30 +0000
════════════════════════
⌗ Tags: #Technology #ANSI escape sequence terminal hiding #automated build log stream exploitation #Claude Code payload detection #indirect prompt injection software safety #Java testing dependencies boycott #jqwik hidden prompt injection #JUnit 5 platform alternative migration #Maven Central supply chain vulnerability #printMessageForCodingAgents source bytecode #protestware open source security risks
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 31 May 2026 10:08:30 +0000
════════════════════════
⌗ Tags: #Technology #ANSI escape sequence terminal hiding #automated build log stream exploitation #Claude Code payload detection #indirect prompt injection software safety #Java testing dependencies boycott #jqwik hidden prompt injection #JUnit 5 platform alternative migration #Maven Central supply chain vulnerability #printMessageForCodingAgents source bytecode #protestware open source security risks
Information Security News
jqwik Hidden Prompt Injection Targets AI Coding Agents
Java testing library jqwik faces major developer backlash after version 1.10.0 deploys a hidden prompt injection payload aimed at tricking AI coding tools.