supply-chain-attack
56 articles with this tag
INFO
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
HIGH
HIGH
CRITICAL
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
INFO
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
SleeperGem attack targets Ruby ecosystem with malicious gems
North Korean PolinRider supply chain attack targets 108 unique repos
North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
22nd June – Threat Intelligence Report
USB drives carrying China-linked malware infected Japanese military networks for nearly a year
From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet
North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels
Miasma worms its way onto GitHub as attack kit goes open source
Microsoft Restores Some GitHub Repos, Keeps Others Offline as Miasma Probe Continues
Four coordinated npm supply chain campaigns active in May–June 2026 — TTPs, IOCs, and detection notes
JINX-0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS Malware
GitHub says internal repos exfiltrated after poisoned VS Code extension attack
Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware
Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages
JDownloader website compromised to distribute malicious installers
PromptMink: ReversingLabs discloses 7-month DPRK supply chain campaign using LLM Optimization (LLMO) to target AI coding agents via npm
Checkmarx Confirms Data Stolen in Supply Chain Attack
Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden
More fake extensions linked to GlassWorm found in Open VSX code marketplace
Researchers Uncover 73 Fake VS Code Extensions Delivering GlassWorm v2 Malware
Bitwarden CLI npm package compromised to steal developer credentials
Trojanized TestDisk installer, Microsoft binary tapped for illicit ScreenConnect deployment
When PUPs Grow Fangs: Dragon Boss Solutions' $10 Supply Chain Risk
OpenAI Revokes macOS App Certificate After Malicious Axios Supply Chain Incident
Do not get high(jacked) off your own supply (chain)
Axios NPM supply chain incident
You Patched LiteLLM, But Do You Know Your AI Blast Radius?
Mercor Hit by LiteLLM Supply Chain Attack
What is TeamPCP Doing? - Threat Wire
Threat Brief: Widespread Impact of the Axios Supply Chain Attack
North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack
the WORST hack of 2026
Emergency Webcast Briefing: Axios NPM Supply Chain Compromise
Axios npm packages backdoored in supply chain attack
Supply chain blast: Top npm package backdoored to drop dirty RAT on dev machines
HUGE supply chain attack
CISA sounds alarm on Langflow RCE, Trivy supply chain compromise after rapid exploitation
Trivy supply chain breach compromises over 1,000 SaaS environments, Lapsus$ joins the extortion wave
From Trivy to Broad OSS Compromise: TeamPCP Hits Docker Hub, VS Code, PyPI
LiteLLM PyPI packages compromised in expanding TeamPCP supply chain attacks
TeamPCP Expands Supply Chain Campaign With LiteLLM PyPI Compromise
PyPI warns developers after LiteLLM malware found stealing cloud and CI/CD credentials
Aqua’s Trivy Vulnerability Scanner Hit by Supply Chain Attack
Trivy Security Scanner GitHub Actions Breached, 75 Tags Hijacked to Steal CI/CD Secrets
Claude Code Security and Magecart: Getting the Threat Model Right
New PhantomRaven NPM attack wave steals dev data via 88 packages
The Future of Supply Chain Backdoor Detections
Hackers may have breached FBI wiretap network via supply chain
Microsoft Warns Developers of Fake Next.js Job Repos Delivering In-Memory Malware
Malicious npm Packages Harvest Crypto Keys, CI Secrets, and API Tokens
Malicious MoltBot skills used to push password-stealing malware
The Chrysalis Backdoor: A Deep Dive into Lotus Blossom’s toolkit
Notepad++ update service hijacked in targeted state-linked attack
eScan Antivirus Update Servers Compromised to Deliver Multi-Stage Malware
AV vendor goes to war with security shop over update server scare