<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><link>https://bsky.app/profile/safetycli.bsky.social</link><title>@safetycli.bsky.social - </title><item><link>https://bsky.app/profile/safetycli.bsky.social/post/3mcqph73o3k2n</link><description>Big shout out to @anthropic.com for their recent $1.5m donation to the @python.org Foundation to help secure the @pypi.org ecosystem.  Great stuff!&#xA;https://pyfound.blogspot.com/2025/12/anthropic-invests-in-python.html?utm_source=tldrdevops</description><pubDate>19 Jan 2026 03:33 +0000</pubDate><guid isPermaLink="false">at://did:plc:nycsxrdr35j75wf52ecagli3/app.bsky.feed.post/3mcqph73o3k2n</guid></item><item><link>https://bsky.app/profile/safetycli.bsky.social/post/3mbshcvkiss2m</link><description>Do you use @polymarket.bsky.social or integrate with their platform?  If so, watch out as threat actors are targeting their users with a malicious NPM package: polymarket-clob.  Read more here:  https://getsafety.com/blog-posts/polymarket-targeted-by-malicious-packages</description><pubDate>07 Jan 2026 02:47 +0000</pubDate><guid isPermaLink="false">at://did:plc:nycsxrdr35j75wf52ecagli3/app.bsky.feed.post/3mbshcvkiss2m</guid></item><item><link>https://bsky.app/profile/safetycli.bsky.social/post/3mbneimxdu22y</link><description>The Safety research team just dropped a killer blog post where we identify eleven malicious NPM packages that are part of the latest Shai-hulud worm campaign.  Check it out at https://getsafety.com/blog-posts/shai-hulud-3-0</description><pubDate>05 Jan 2026 02:14 +0000</pubDate><guid isPermaLink="false">at://did:plc:nycsxrdr35j75wf52ecagli3/app.bsky.feed.post/3mbneimxdu22y</guid></item><item><link>https://bsky.app/profile/safetycli.bsky.social/post/3m5wwvfof4c2q</link><description>The Safety research team has identified a new NPM based malware we are calling &#34;Integrator-Filescrypt&#34;.  This campaign uses a unique &#34;cloaking&#34; technique to hide from researchers and cloud providers.  It&#39;s sneaky &amp; very effective.  Read more on our blog:  https://www.getsafety.com/blog-posts/npm-malware-uses-cloaking</description><pubDate>18 Nov 2025 23:56 +0000</pubDate><guid isPermaLink="false">at://did:plc:nycsxrdr35j75wf52ecagli3/app.bsky.feed.post/3m5wwvfof4c2q</guid></item><item><link>https://bsky.app/profile/safetycli.bsky.social/post/3m5juykgt6f2c</link><description>Safety is on @bsky.app!</description><pubDate>13 Nov 2025 19:17 +0000</pubDate><guid isPermaLink="false">at://did:plc:nycsxrdr35j75wf52ecagli3/app.bsky.feed.post/3m5juykgt6f2c</guid></item></channel></rss>