Tag: supply-chain
-
Shai-Hulud Attack Nips Cyber-Firm CrowdSec’s GitHub Data
Threat actors stole 170 private repositories using an OAuth token stolen from a former employee’s computer through the TanStack npm supply chain attack. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/shai-hulud-attack-cyber-firm-crowdsec-github-data
-
Hackers Compromise 65 GitHub Repositories and Poison npm Package With Hidden Backdoor
Threat actors have compromised at least 65 public GitHub repositories in a software supply-chain campaign that abused npm trusted publishing to distribute a stealthy backdoor through a legitimate package. The malicious package was identified as @dforge-core/dforge-mcp, an MCP-related npm package whose maintainer account was abused for roughly 105 minutes on September 9. Attackers initially pushed…
-
NIS2 wirkt bis in den Mittelstand: Neues FitNIS2-Projekt nimmt Lieferketten ins Visier
FitNIS2 Lieferkette hilft KMU, indirekte NIS2-Anforderungen zu erkennen, Cyberrisiken zu priorisieren und Sicherheitsmaßnahmen nachvollziehbar zu dokumentieren. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/nis2-wirkt-bis-in-den-mittelstand-neues-fitnis2-projekt-nimmt-lieferketten-ins-visier/a46442/
-
10 Malicious npm Packages Linked to Runtime Malware Campaign With Millions of Downloads
A sophisticated npm supply-chain campaign has been linked to 10 malicious JavaScript packages that collectively recorded millions of downloads while bypassing npm’s lifecycle-script protections. The operation centers on a counterfeit package named indexed-btree, which impersonates the legitimate sorted-btree library and executes its malware only when an application uses the package at runtime. Unlike conventional npm…
-
HEIF Heist Image Flaws Let Attackers Gain RCE Across Meta, Slack and GitHub Enterprise
Tags: attack, cyber, data, flaw, github, malicious, rce, remote-code-execution, supply-chain, technology, threat“HEIF Heist,” a broad class of image-processing attack paths that could allow threat actors to turn malicious HEIF, HEIC, and AVIF uploads into remote code execution, sensitive-data exposure, and account compromise across major technology and enterprise platforms. The research, published by Hacktron, highlights a familiar but increasingly dangerous supply-chain weakness: applications often trust native image-decoding…
-
Hackers Exploit TanStack Supply Chain Attack to Steal 170 Private CrowdSec Repositories
Threat actors linked to the TanStack npm supply chain compromise allegedly used a stolen GitHub OAuth token to clone about 170 private CrowdSec repositories, exposing source code, limited contact information, and a restricted AWS notification credential. CrowdSec stated that the compromise originated from a former employee’s account, which remained in the company’s GitHub organization for…
-
Hackers Exploit TanStack Supply Chain Attack to Steal 170 Private CrowdSec Repositories
Threat actors linked to the TanStack npm supply chain compromise allegedly used a stolen GitHub OAuth token to clone about 170 private CrowdSec repositories, exposing source code, limited contact information, and a restricted AWS notification credential. CrowdSec stated that the compromise originated from a former employee’s account, which remained in the company’s GitHub organization for…
-
Hackers Exploit TanStack Supply Chain Attack to Steal 170 Private CrowdSec Repositories
Threat actors linked to the TanStack npm supply chain compromise allegedly used a stolen GitHub OAuth token to clone about 170 private CrowdSec repositories, exposing source code, limited contact information, and a restricted AWS notification credential. CrowdSec stated that the compromise originated from a former employee’s account, which remained in the company’s GitHub organization for…
-
Malicious npm packages evade install-script defenses at runtime
An ongoing npm malware campaign involving the ‘indexed-btree’ package shows how threat actors bypass supply chain defenses by hiding malicious code in a package’s normal runtime behavior rather than in installation scripts. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/malicious-npm-packages-evade-install-script-defenses-at-runtime/
-
An undercover Google analyst infiltrated a notorious supply-chain hacking gang
Google’s threat intelligence group said it had a mole inside TeamPCP’s inner circle. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/09/an-undercover-google-analyst-infiltrated-a-notorious-supply-chain-hacking-gang/
-
CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
An attacker copied about 170 of CrowdSec’s private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18.The French security company had kept his GitHub access open. CrowdSec says his laptop was compromised in May’s supply chain attack on TanStack, in which malicious versions of…
-
Brevo Supply-Chain Attack Infected Over 100,000 Websites
A Brevo supply-chain attack used compromised Cloudflare access to inject malware into websites, potentially affecting over 100,000 sites. Brevo, formerly known as Sendinblue, is a French cloud-based marketing and customer communication platform whose clients include eBay, Louis Vuitton and Michelin. The company was first compromised on September 10, when attackers exploited a vulnerability in its…
-
An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang
TeamPCP pulled off the worst-ever software supply-chain hacking spree and breached thousands of companies. Now Google’s threat intelligence group says it had a mole inside the hackers’ inner circle. First seen on wired.com Jump to article: www.wired.com/story/an-undercover-google-analyst-infiltrated-a-notorious-supply-chain-hacking-gang/
-
An Undercover Google Analyst Infiltrated a Notorious Supply Chain Hacking Gang
TeamPCP pulled off the worst-ever software supply chain hacking spree and breached thousands of companies. Now Google’s threat intelligence group says it had a mole inside the hackers’ inner circle. First seen on wired.com Jump to article: www.wired.com/story/an-undercover-google-analyst-infiltrated-a-notorious-supply-chain-hacking-gang/
-
Software Supply Chain Security – Wenn Open-Source-Pakete zur Hintertür werden
First seen on security-insider.de Jump to article: www.security-insider.de/operation-navy-ghost-backdoor-supply-chain-a-a7aef14bca7ea71dbb268aaf312f2b5f/
-
Plugin4Shell Zero-Click RCE Hits Claude Code, Codex, Copilot and Gemini CLI
A newly disclosed vulnerability known as Plugin4Shell reveals a supply chain weakness in major AI coding agents. This flaw allows attackers to replace trusted, SHA-pinned plugins with malicious code, enabling remote code execution without user interaction. Researchers Or Nevo, Dor Granat, and Niv Hoffman have identified that the issue impacts Anthropic Claude Code, OpenAI Codex,…
-
Brevo supply-chain attack injected ClickFix scripts on customer sites
Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/brevo-supply-chain-attack-injected-clickfix-scripts-on-customer-sites/
-
CISOs to Watch in the Twin Cities: From State Government to the Supply Chain
The Twin Cities economy runs on managed care, medical devices, and a state government that has professionalized its own security leadership as thoroughly as any private employer here. The seven leaders below secure a regional health plan, a medical device… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/cisos-to-watch-in-the-twin-cities-from-state-government-to-the-supply-chain/
-
Maximum Severity GitLab Flaw Puts Supply Chains at Risk
CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/maximum-severity-gitlab-flaw-supply-chains-risk
-
Security Affairs newsletter Round 594 by Pierluigi Paganini INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. The AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open…
-
Daily OT Security News: September 13, 2026
Today’s OT-security briefing collects reported developments that affect operational technology, network infrastructure, supply chains, and incident response posture across multiple industrial and critical”‘infrastructure sectors. The summaries below focus on factual takeaways relevant to operators, security teams, and resilience planners without… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/daily-ot-security-news-september-13-2026/
-
OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
The “major malicious attack” that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx.On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated cyber…
-
Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data
Threat actors are increasingly using Claude-based AI workflows to automate cyberattacks, accelerate data theft, and reduce the technical expertise needed to run complex intrusions. Anthropic’s report details cyber espionage, financially motivated extortion, supply-chain compromise, and hacktivist activity disrupted between December 2025 and August 2026. Rather than using an AI chatbot only for occasional coding assistance,…
-
The AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open Internet
Researchers found 36,769 exposed AI endpoints, but only 2% had an HTTP authentication gate. Running AI locally is supposed to give organizations more control. Models, prompts and documents stay on infrastructure they manage instead of being sent to a third-party cloud. But that advantage disappears quickly when the infrastructure itself is exposed to the public…
-
AI Coding Tools Now a Prime Target for Threat Actors, Google Warns
Google warned that the rapid integration of AI-assisted coding tools has significantly expanded software supply chain risks First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ai-coding-tools-threat-actors/
-
Trezor Supply Chain Breach Now Impacts 81,000 Customers
Crypto wallet-maker Trezor says a data breach at supplier ShipMonk is far worse than originally thought First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/trezor-supply-chain-breach-impacts/
-
Hackers Hijack Coder Module Registry to Distribute Credential-Stealing Malicious Packages
Coder has reported a significant software supply chain incident in which an unidentified threat actor redirected part of its official module registry traffic to attacker-controlled infrastructure. This led to the temporary distribution of tampered Terraform modules intended to steal credentials. The incident affected the registry at registry.coder.com on August 31, 2026, between 07:35 UTC and…
-
Known npm Worm Returns After 111 Days and Security Scanning Still Let It Through
A known Shai-Hulud npm worm payload has resurfaced after 111 days of inactivity, raising fresh questions about the effectiveness of registry-level malware screening. The May campaign demonstrated how quickly a single compromised maintainer account can turn into a software supply-chain incident. Attackers pushed malicious versions across npm packages, including widely used visualization and frontend dependencies.…
-
âš¡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on.Elsewhere, a trusted software source delivered code that stole…

