A massive supply chain attack on the Node Package Manager (npm) registry has infected over 400 packages with over 2 billion downloads with the ...
Microsoft has aligned VS Code's existing agent-plugin feature with a vendor-neutral format for portable skills and MCP servers.
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems ...
A Keyv-linked npm worm poisoned 353 versions across 79 package names, stealing developer and CI credentials while repository ...
Five free Marketplace extensions promise private, locally run coding assistance as developers look for alternatives to metered cloud AI.
I installed over 100 Claude Code plugins so you don't have to. Here's the signal from the noise.