Skip to content
feed: live
>_ 0dayNews
Vendor

Supply Chain

Attacks that use the software supply chain as the delivery vector — malicious npm, PyPI, and RubyGems packages, poisoned transitive dependencies, typo-squats, and compromised build pipelines. Includes DPRK's ongoing Contagious Interview package operations and the rollup-polyfill class of "one dependency, many downstreams" incidents.

Articles
~/articles/2026-07-11-jscrambler-npm-8-14-0-preinstall-rust-infostealer
jscrambler 8.14.0 npm hijack: Rust stealer on install
● Breaking
supply chain

jscrambler 8.14.0 npm hijack: Rust stealer on install

Malicious jscrambler 8.14.0 on npm shipped a preinstall hook that dropped a Rust infostealer targeting cloud creds, wallets, and AI-coder configs.

read →
~/articles/2026-07-10-openmandriva-beatrici-cooker-cosmic-gnome-admin-boundary
OpenMandriva contributor deleted GNOME and Cosmic repos
Analysis
supply chain

OpenMandriva contributor deleted GNOME and Cosmic repos

Davide Beatrici, a three-year OpenMandriva admin, deleted the Cosmic and GNOME repositories and pushed an obsoleting empty package into Cooker on July 8.

read →
~/articles/2026-07-11-npm-12-allowscripts-off-default-gats-oidc-branch
npm 12 turns install scripts off by default
Analysis
supply chain

npm 12 turns install scripts off by default

npm 12 defaults allowScripts to off and deprecates 2FA-bypass tokens. Closes the install-hook branch; does not touch the maintainer-account one.

read →
~/articles/2026-07-10-injective-sdk-ts-npm-oidc-thomasralee
Injective SDK's npm compromise, and the OIDC that let it
Analysis
supply chain

Injective SDK's npm compromise, and the OIDC that let it

@injectivelabs/sdk-ts@1.20.21 shipped a wallet-key exfiltration routine for two days. A maintainer account walked it through the OIDC publisher pipeline.

read →
~/articles/2026-07-10-binarly-uboot-six-flaws-fit-signature-verification
Six U-Boot bugs sit in front of the signature check
Analysis
supply chain

Six U-Boot bugs sit in front of the signature check

Binarly disclosed six flaws in U-Boot's FIT image parser. Two allow code execution, four are DoS, all reached before the signature check runs.

read →
~/articles/2026-07-09-openmandriva-beatrici-mumble-contributor-repo-sabotage
OpenMandriva ex-contributor wipes GNOME, Cosmic packages
supply chain

OpenMandriva ex-contributor wipes GNOME, Cosmic packages

Mumble developer Davide Beatrici used leftover admin from a repo migration to delete OpenMandriva GitHub content and obsolete GNOME, Cosmic packages.

read →
~/articles/2026-07-09-injectivelabs-sdk-ts-npm-1-20-21-wallet-stealer
Injective SDK 1.20.21 on npm shipped a wallet stealer
supply chain

Injective SDK 1.20.21 on npm shipped a wallet stealer

Attacker pushed @injectivelabs/sdk-ts 1.20.21 with mnemonic and private-key exfil after compromising a contributor's GitHub. 310 installs before the pull.

read →
~/articles/2026-07-09-npm-12-install-scripts-off-default-github-gat-deprecation
npm 12 flips install scripts off by default
Analysis
supply chain

npm 12 flips install scripts off by default

npm 12 lands with allowScripts, --allow-git, and --allow-remote all defaulting to none. GitHub is also winding down GATs that skip 2FA. The default just moved.

read →
~/articles/2026-07-08-socket-paysafe-skrill-npm-pypi-fake-sdks
Socket: 17 fake Paysafe, Skrill, Neteller SDKs on npm and PyPI
supply chain

Socket: 17 fake Paysafe, Skrill, Neteller SDKs on npm and PyPI

Socket disclosed 17 malicious packages posing as Paysafe, Skrill, and Neteller SDKs across npm and PyPI. Payload steals payment API keys, AWS keys, and GitHub/npm tokens.

read →
~/articles/2026-07-08-hallusquatting-npm-ai-hallucinated-packages-tel-aviv
HalluSquatting weaponizes AI-hallucinated npm packages
supply chain

HalluSquatting weaponizes AI-hallucinated npm packages

Tel Aviv researchers register the fake package names AI coding assistants keep inventing. Up to 100% hit rate on skill installs, no confirmed exploitation yet.

read →
~/articles/2026-07-08-github-verified-commit-hash-malleability-ginesin
A signed Git commit's hash is not a unique fingerprint
Analysis
supply chain

A signed Git commit's hash is not a unique fingerprint

Carnegie Mellon research shows a signed Git commit can be re-minted with a different hash but the same 'Verified' badge — no signing key required, no code changed.

read →
~/articles/2026-07-06-skillcloak-scanners-miss-agent-skill-malware-hkust
SkillCloak: Scanners Miss 90%+ of Skill Malware
supply chain

SkillCloak: Scanners Miss 90%+ of Skill Malware

HKUST researchers show static scanners for AI agent skill marketplaces miss over 90% of malware repackaged with simple tricks. If you rely on them, that gate is broken.

read →
~/articles/2026-07-05-jfrog-rollup-polyfill-npm-six-packages-follow-up
Four More Rollup Polyfill Typosquats Surface
supply chain

Four More Rollup Polyfill Typosquats Surface

JFrog's disclosure names six npm packages in the Rollup polyfill typosquat cluster, not two. The extra four sit inside the same infrastructure the earlier reporting described, and the audit surface hasn't moved.

read →
~/articles/2026-07-04-polinrider-108-dprk-packages-contagious-interview
PolinRider: DPRK Seeds 108 Malicious Packages
supply chain

PolinRider: DPRK Seeds 108 Malicious Packages

The Hacker News reports 108 malicious npm, Packagist, Go, and Chrome extension listings tied to the DPRK Contagious Interview cluster. Here's what a dev shop actually does about it this week.

read →
~/articles/2026-07-03-chocopoc-rat-fake-poc-github-pypi-yeswehack
ChocoPoC: Fake CVE PoC Repos Ship a Stealer
supply chain

ChocoPoC: Fake CVE PoC Repos Ship a Stealer

YesWeHack and Sekoia disclosed a stealer campaign hiding inside GitHub PoC repos and PyPI packages, targeting the researchers who clone them. Treat every fresh 'PoC for hot CVE' repo as hostile until you've read every dependency.

read →
~/articles/2026-07-03-fatfs-runzero-seven-flaws-embedded-firmware
runZero Discloses Seven FatFs Firmware Flaws
supply chain

runZero Discloses Seven FatFs Firmware Flaws

runZero disclosed seven vulnerabilities in FatFs, a small filesystem library shipped inside ESP-IDF, STM32Cube, Zephyr, MicroPython, and other embedded stacks. Only one has an upstream fix.

read →
~/articles/2026-07-03-dprk-npm-rollup-polyfill-supply-chain
DPRK npm Packages Impersonate a Rollup Polyfill
Analysis
supply chain

DPRK npm Packages Impersonate a Rollup Polyfill

JFrog links two new malicious npm packages — impersonating a Rollup polyfill project down to its metadata — to a DPRK cluster after developer secrets and remote access.

read →