kapynDev Tools

For the 2nd time in weeks, Microsoft packages laced with credential stealer

Security researchers discovered 73 malicious npm packages disguised as legitimate AI tools. These packages immediately execute a credential-stealing malware upon installation, posing a significant risk to developers, especially those working with AI agents. This incident highlights the ongoing threat of supply chain attacks within the developer ecosystem.

Ars Technica·Jun 8, 2026

Opening Kapyn…