
safedep.io
June 8, 2026
10 min read
47/100
Summary
Config files in repositories can execute code automatically when opened by development tools, potentially allowing attackers to run malicious code without the developer's awareness. Tools such as VS Code, Cursor, Claude Code, Gemini CLI, npm, Composer, and Bundler can read and act on these config files.
Key Takeaways

Keyv and friends compromised in active Shai-Hulud supply chain attack
Aug 4, 2026

Shai-Hulud Themed Malware Found in the PyTorch Lightning AI Training Library
Apr 30, 2026

Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware
Aug 7, 2026

Axios compromised on NPM – Malicious versions drop remote access trojan
Mar 31, 2026

Glassworm Is Back: A New Wave of Invisible Unicode Attacks Hits Repositories
Mar 15, 2026