supply-chain-attack
64 articles with this tag
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
HIGH
HIGH
CRITICAL
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
INFO
Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more
Coder platform targeted by attackers delivering malicious Terraform modules
BGP hijack infecting networks caused by a comedy of errors that’s not funny at all
Hackers Just Poisoned the Rust Supply Chain | Threat Wire
Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more
Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain
Hackers compromise Rust crate arrayref to inject malware
Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack
Massive supply-chain attack compromises 440 packages under four hours
SleeperGem attack targets Ruby ecosystem with malicious gems
North Korean PolinRider supply chain attack targets 108 unique repos
North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
22nd June – Threat Intelligence Report
USB drives carrying China-linked malware infected Japanese military networks for nearly a year
From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet
North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels
Miasma worms its way onto GitHub as attack kit goes open source
Microsoft Restores Some GitHub Repos, Keeps Others Offline as Miasma Probe Continues
Four coordinated npm supply chain campaigns active in May–June 2026 — TTPs, IOCs, and detection notes
JINX-0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS Malware
GitHub says internal repos exfiltrated after poisoned VS Code extension attack
Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware
Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages
JDownloader website compromised to distribute malicious installers
PromptMink: ReversingLabs discloses 7-month DPRK supply chain campaign using LLM Optimization (LLMO) to target AI coding agents via npm
Checkmarx Confirms Data Stolen in Supply Chain Attack
Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden
More fake extensions linked to GlassWorm found in Open VSX code marketplace
Researchers Uncover 73 Fake VS Code Extensions Delivering GlassWorm v2 Malware
Bitwarden CLI npm package compromised to steal developer credentials
Trojanized TestDisk installer, Microsoft binary tapped for illicit ScreenConnect deployment
When PUPs Grow Fangs: Dragon Boss Solutions' $10 Supply Chain Risk
OpenAI Revokes macOS App Certificate After Malicious Axios Supply Chain Incident
Do not get high(jacked) off your own supply (chain)
Axios NPM supply chain incident
You Patched LiteLLM, But Do You Know Your AI Blast Radius?
Mercor Hit by LiteLLM Supply Chain Attack
What is TeamPCP Doing? - Threat Wire
Threat Brief: Widespread Impact of the Axios Supply Chain Attack
North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack
the WORST hack of 2026
Emergency Webcast Briefing: Axios NPM Supply Chain Compromise
Axios npm packages backdoored in supply chain attack
Supply chain blast: Top npm package backdoored to drop dirty RAT on dev machines
HUGE supply chain attack
CISA sounds alarm on Langflow RCE, Trivy supply chain compromise after rapid exploitation
Trivy supply chain breach compromises over 1,000 SaaS environments, Lapsus$ joins the extortion wave
From Trivy to Broad OSS Compromise: TeamPCP Hits Docker Hub, VS Code, PyPI
LiteLLM PyPI packages compromised in expanding TeamPCP supply chain attacks
TeamPCP Expands Supply Chain Campaign With LiteLLM PyPI Compromise
PyPI warns developers after LiteLLM malware found stealing cloud and CI/CD credentials
Aqua’s Trivy Vulnerability Scanner Hit by Supply Chain Attack
Trivy Security Scanner GitHub Actions Breached, 75 Tags Hijacked to Steal CI/CD Secrets
Claude Code Security and Magecart: Getting the Threat Model Right
New PhantomRaven NPM attack wave steals dev data via 88 packages
The Future of Supply Chain Backdoor Detections
Hackers may have breached FBI wiretap network via supply chain
Microsoft Warns Developers of Fake Next.js Job Repos Delivering In-Memory Malware
Malicious npm Packages Harvest Crypto Keys, CI Secrets, and API Tokens
Malicious MoltBot skills used to push password-stealing malware
The Chrysalis Backdoor: A Deep Dive into Lotus Blossom’s toolkit
Notepad++ update service hijacked in targeted state-linked attack
eScan Antivirus Update Servers Compromised to Deliver Multi-Stage Malware
AV vendor goes to war with security shop over update server scare