
Research
/Security News
PolinRider Spreads Through Compromised GitHub Accounts and Packagist
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.
mcp-attest-cli
Advanced tools
CLI for MCP tool-manifest attestation: keygen, sign, verify, inspect, fingerprint, check-pin.
FAQs
CLI for MCP tool-manifest attestation: keygen, sign, verify, inspect, fingerprint, check-pin.
The npm package mcp-attest-cli receives a total of 7 weekly downloads. As such, mcp-attest-cli popularity was classified as not popular.
We found that mcp-attest-cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.

Company News
Allow myself to introduce... myself.