supply-chain 60
- Malicious npm Package Exfiltrated Files from Claude AI User Directories
- SymJack Attack Weaponizes AI Coding Agents as Supply Chain Delivery Systems
- Laravel-Lang Packages Poisoned to Exfiltrate CI Secrets
- Megalodon Supply Chain Attack Infects 5,500+ GitHub Repositories
- npm Launches Staged Publishing with 2FA Gating to Counter Supply Chain Attacks
- Packagist Supply Chain Attack Injects Linux Malware Into 8 Composer Packages
- Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer
- Megalodon GitHub Attack Injects Malicious CI/CD Workflows into 5,561 Repos
- Grafana Codebase Stolen via TanStack Supply Chain Attack
- Over 320 NPM Packages Hit by Fresh Mini Shai-Hulud Supply Chain Attack
- Unit 42: TamperedChef Clusters Deliver Stealthy Payloads via Trojanized Productivity Apps
- GitHub Confirms 3,800 Internal Repos Breached via Malicious VS Code Extension
- Grafana Labs Source Code Exposed via GitHub Breach Linked to TanStack npm Attack
- New Shai-Hulud Wave Compromises 600+ npm Packages in Fresh Supply Chain Hit
- Compromised Nx Console 18.95.0 Delivers Credential Stealer to 2.2M VS Code Users
- GitHub Actions Supply Chain Attack Hijacks actions-cool/issues-helper Tags
- node-ipc npm Package Compromised in Supply Chain Attack to Steal Credentials
- TanStack Supply Chain Attack Compromised Two OpenAI Employee Devices, Credentials Stolen
- TeamPCP Releases Shai-Hulud Worm Source Code, Invites Supply Chain Attacks with Monetary Rewards
- TanStack npm Supply Chain Attack Hits Multiple AI Companies
- Hugging Face Model Tokenizer Files Can Be Weaponized to Hijack Outputs and Exfiltrate Data
- Official Checkmarx Jenkins AST Plugin Backdoored with Infostealer
- Mini Shai-Hulud: Dissecting the SAP CAP npm Supply Chain Worm
- JDownloader Website Compromised to Distribute Python RAT via Malicious Installers
- Dozen Critical Vulnerabilities in vm2 Node.js Library Enable Sandbox Escape and RCE
- DAEMON Tools Supply Chain Attack Hits Government and Scientific Targets
- New Quasar Linux Malware Targets Software Developers with Rootkit and Backdoor
- Trellix Source Code Breach Exposes Security Product Internals
- DAEMON Tools Official Installers Backdoored in Supply Chain Attack
- ScarCruft Compromises Gaming Platform to Deploy BirdCall Backdoor on Android and Windows
- Backdoored PyTorch Lightning Package on PyPI Delivers Credential Stealer
- Trellix Discloses Data Breach After Source Code Repository Hack
- Trellix Confirms Source Code Breach via Unauthorized Repository Access
- TeamPCP 'Mini Shai-Hulud' Supply Chain Attack Hits SAP npm Packages
- PyTorch Lightning Compromised in PyPI Supply Chain Attack to Steal Credentials
- Critical Gemini CLI Flaw Enabled Host Code Execution and Supply Chain Attacks
- Google Patches CVSS 10 Gemini CLI RCE Enabling Supply-Chain Code Execution
- WordPress Redirect Plugin Hid Dormant Backdoor for Five Years Across 70,000 Sites
- SAP npm Packages Compromised in Credential-Stealing Supply Chain Attack
- Vect 2.0 Ransomware Behaves as Wiper Due to Encryption Design Flaw
- DPRK Threat Actors Use Claude Opus to Plant Malicious npm Packages
- PyPI Package 'elementary-data' with 1.1M Monthly Downloads Backdoored to Steal Credentials
- Checkmarx Confirms GitHub Repository Data Published on Dark Web After March Supply Chain Attack
- 73 Fake VS Code Extensions on Open VSX Deliver GlassWorm v2 Infostealer
- Unit 42 Maps npm Attack Surface: Wormable Malware, CI/CD Persistence, and Multi-Stage Chains
- Bitwarden npm Supply Chain Attack Attributed to TeamPCP; Shai-Hulud Worm Component Identified
- Checkmarx Supply Chain Attack Compromises Bitwarden CLI and KICS Analysis Tool
- Vercel Expands Breach Scope: More Accounts Compromised in Context.ai-Linked Incident
- CVE-2026-1731: Critical Bomgar RMM RCE Actively Exploited to Spread Ransomware
- 26 Malicious Crypto Wallet Apps Found in China's Apple App Store
- Vercel Breach Traced to Context.ai Third-Party Compromise
- 30+ EssentialPlugin WordPress Plugins Backdoored in Supply Chain Compromise
- OpenAI Rotates macOS Code-Signing Certs After North Korea-Linked Axios Supply Chain Attack
- DoD Flags Anthropic as Supply-Chain Risk While Trump Officials Push Banks to Test Mythos
- CPUID Supply Chain Attack Poisons CPU-Z and HWMonitor Downloads
- Smart Slider 3 Pro Update System Hijacked to Deliver Backdoored WordPress and Joomla Versions
- ClipBanker Malware Distributed via Trojanized Proxifier in Multi-Stage Attack Chain
- Microsoft Suspends Developer Accounts for High-Profile Open Source Projects
- Dissecting the LiteLLM Kill Chain
- LiteLLM Supply Chain Attack — PyPI Packages Compromised