June 29, 2026
It is a Tuesday morning. A developer pulls a popular open-source package, one they have installed a hundred times, and runs the install. Nothing looks wrong: the progress bar fills, the prompt returns, they move on. What they cannot see is that the version they just pulled went up four hours ago, and that buried in its install script are a few lines that read their SSH keys and environment variables and post them to a server they have never heard of. By the time an advisory is filed, the keys are already gone.
Read the article →