Rohan Prabhu / Step Safety Blog:
Researchers discovered several packages in the @redhat-cloud-services npm namespace containing malware targeting credentials for GitHub Actions, AWS, GCP and others.— Several packages in the @redhat-cloud-services npm scope contain malicious payloads that are triggered via a preinstallation hook every time npm is installed.
Trending
- Researchers discovered several packages in the @redhat-cloud-services npm namespace containing malware targeting credentials for GitHub Actions, AWS, GCP and others (Rohan Prabhu/Step Security Blog)
- Union work stoppage threatens GM truck production
- Sekai, which lets users create mini apps via text prompts, raised a $20 million Series A round co-led by Khosla Ventures and Connect Ventures, following a $6 million seed in 2025 (Kerry Flynn/Axios)
- The emergence of Uzbekistan as a mobility hub in Central Asia – The Diplomat
- Democrats figured out how to kill Trump’s weapons fund
- Barry Diller’s People to offer $18 billion for casino giant
- SEC Filing: Strategy sold 32 bitcoins between May 26 and 31 for approximately $2.5 million at an average net price of $77,135 per coin, its first disclosed bitcoin disposition (CoinDesk)
- Retail profits in Q1 2026 fueled by tax refunds and BNPL

