Javascript stories
The tool has already blocked more than 52,000 risky npm packages as supply chain attacks continue to hit software teams.
Burnout is rising as marketers race to master AI, while more than 70% of teams now work beyond sustainable capacity.
CrowdStrike said state-backed espionage and extortion are surging as AI assets inside tech groups draw hackers seeking code, models and access.
The deal gives the web giant a direct role in a tool used in 129 million weekly downloads, while keeping it open source and vendor-neutral.
Developers using npm could have secrets exposed as 176 malicious packages were set up to hijack dependency resolution and run postinstall malware.
Software teams can now tackle sprawling code audits and migrations with parallel AI subagents, though the feature uses more tokens and needs approval.
Enterprises running AI agents can now cut infrastructure overhead, as MongoDB adds automated embeddings, memory and faster database performance.
Organisations using AI in software development will get training on secure coding and governance as vulnerabilities and data risks mount.
Detection of malicious code can collapse when AI reviewers are fed large files packed with harmless text, Cloudflare's research shows.
Hundreds of packages could have exposed API keys and logins after Claude Code saved approved commands in a file npm may publish by default.
A shortage of experienced coders is putting pressure on teams maintaining mission-critical web systems as most PHP users plan upgrades.
Broad exposure across thousands of applications is feared after Google tied the axios npm supply chain attack to suspected North Korean hackers.
Google has launched Antigravity, a full-stack coding agent in AI Studio that turns text prompts into collaborative, production-ready web apps.
Malicious fake Windsurf IDE extension hid JavaScript, abused Solana to fetch payloads, and stole developers' browser credentials and tokens.
Ransomware group LeakNet adopts ClickFix lures and a Deno-based fileless loader to scale attacks and evade traditional endpoint defences.
Okta and partners pull rogue ShieldGuard Chrome extension that stole crypto wallet data and bypassed browser defences via custom code.
Chainguard expands its rebuilt-from-source Libraries to Python, Java and JavaScript, targeting malware risks in AI-driven software supply chains.
Meta hands React and React Native to a new Linux Foundation-backed React Foundation, promising neutral, community-led governance.
ActiveState launches a 79m-component secure open source catalogue to centralise software supply chains and cut enterprise vulnerability risk.
A free account could have let attackers alter Zapier-maintained packages and hijack logged-in users' browser sessions, researchers said.