News
Product news and updates from the Gastropod team.
-
16 Typosquatted RubyGems Packages Delivered a Windows Infostealer Through the Native Build Proces
Published on gastropod.io on 08-27-2026
-
Fourteen npm Packages Working as intended (except for that pesky Linux Backdoor feature)
Published on gastropod.io on 08-26-2026
-
GeoServer's SQL Injection Zero-Day Was Being Scanned For Within Hours of the (irresponsible) Disclosure
Published on gastropod.io on 08-16-2026
-
Nearly 800 npm Packages, AI-Generated Names, One Shared Backdoor: Inside WEL1DROPPER
Published on gastropod.io on 08-14-2026
-
One Endpoint, Full Admin: Inside the Metabase Bug CISA Says to Patch ASAP
Published on gastropod.io on 08-14-2026
-
14,090 Vulnerabilities in Two Months, and 99.4% of Them Have No CVE
Published on gastropod.io on 08-06-2026
-
77 Counterfeit Open VSX Extensions, with a Config File That Keeps Installing The
Published on gastropod.io on 08-05-2026
-
New npm compromise: The keyv Worm Published Releases That Had No Commit Behind Them
Published on gastropod.io - 08-05-2026
-
ApostropheCMS's Critical Auth Bypass
Published on gastropod.io on 08-01-2026
-
No Login Required: TeamCity's Critical RCE and Your Build
Published on gastropod.io - 07-28-2026
-
PyPI and GitHub Are Racing Against Time for Package Poisoning
Published on gastropod.io on 07-28-2026
-
fastjson 1.x CVE-2026-16723 - yikes!
Published on gastropod.io on 07-25-2026
-
Langflow's Fifth CIS-KEV CVE in a year
Published on gastropod.io on 07-24-2026
-
Borrowed Compute: How Ten Packagist Libraries Turned GitHub Actions Into an Attack Botnet
Published on gastropod.io on 07-23-2026
-
What the OpenAI/Hugging Face Breach Says About SBOM Blind Spots
Published on gastropod.io - 07-22-2026
-
FakeGit: 7,600 Repos, 14 Million Downloads, and an AI Agent Reading the Attacker's README
Published on gastropod.io - 07-22-2026
-
ViteVenom: expansion of the ChainVeil campaign
Published on gastropod.io - 07-21-2026
-
Eleven Bytes, No CVE: The OpenSSL HollowByte Flaw That Scanners Miss
Published on gastropod.io - 07-20-2026
-
SleeperGem: Dormant RubyGems Accounts Reactivated to Deliver a Persistent Backdoor
Published on gastropod.io - 07-19-2026
-
Inside the Injective SDK Wallet-Key Theft
Published on gastropod.io - 07-17-2026
-
Asyncapi NPM Supply Chain Attack
Published on gastropod.io on 07-16-2026
-
The npm Package That Only Turned Evil When You Used It
Published on gastropod.io - 07-15-2026
-
Braintree.net nuget Typosquat
Published on gastropod.io - 07-15-2026
-
Laravel lang tag rewrite supply chain attack
Published on gastropod.io on 07-15-2026
-
Paysafe/Skrill/Neteller fake SDK/Typosquat Campaign
Published on gastropod.io - 07-15-2026
-
The jscrambler npm Compromise
Published on gastropod.io - 7-15-2026
-
Inside the AsyncAPI "Miasma" Attack: When the Pipeline Itself Becomes the Attacker
Published on gastropod.io 7-15-2026
-
gastropod - a superior alternative to Artifactory or Nexus
Gastropod.io is a superior alternative to JFrog Artifactory and Sonatype Nexus because it provides a unified software-supply-chain registry where every artifact leaves a comprehensive trail. Unlike…
-
Introducing Gastropod
Gastropod is an artifact registry that treats identity as the foundation, not an afterthought. Every package — whatever ecosystem it came from — is named by its Package URL:…