Skip to content
feed: live
>_0dayNews
← All vendors
Vendor

Supply Chain

Attacks that use the software supply chain as the delivery vector — malicious npm, PyPI, and RubyGems packages, poisoned transitive dependencies, typo-squats, and compromised build pipelines. Includes DPRK's ongoing Contagious Interview package operations and the rollup-polyfill class of "one dependency, many downstreams" incidents.

0 CVEs43 articlesRSS
Articles
~/articles/2026-08-15-trivy-not-litellm-supply-chain-march
Trivy, Not LiteLLM, Drove the March Supply Chain Breach
Analysis
supply chain

Trivy, Not LiteLLM, Drove the March Supply Chain Breach

SOCRadar's forensics show 95% of the 2,188 affected orgs were compromised via the Trivy scanner before any LiteLLM package was poisoned.

read →
~/articles/2026-08-13-trezor-shipmonk-breach-14k-customers
Trezor Breach: 14,000 Customers Exposed via ShipMonk Hack
supply chain

Trezor Breach: 14,000 Customers Exposed via ShipMonk Hack

Trezor disclosed a breach hitting nearly 14,000 customers after shipping partner ShipMonk was compromised. No device or key exposure. Customer order data is the risk.

read →
~/articles/2026-08-12-litellm-supply-chain-trivy-hack-2500-orgs
LiteLLM Supply Chain Attack Hit 2,500+ Orgs
supply chain

LiteLLM Supply Chain Attack Hit 2,500+ Orgs

Two backdoored LiteLLM PyPI releases sat live for 40 minutes in March, harvesting cloud keys, SSH keys, and Kubernetes tokens. CloudSEK maps exposure to 2,500+ organizations.

read →
~/articles/2026-08-10-bdthemes-supply-chain-wordpress-rogue-admins
BdThemes Supply Chain Creates Rogue WordPress Admins
supply chain

BdThemes Supply Chain Creates Rogue WordPress Admins

A supply-chain attack against BdThemes poisoned a remote JSON feed to install rogue admin accounts on WordPress sites running their plugins. Audit your admin users now.

read →
~/articles/2026-08-06-n-able-n-central-cve-2026-18577-kev-auth-bypass
CISA Flags N-able N-central Auth Bypass — Patch Before Today's Deadline
supply chain

CISA Flags N-able N-central Auth Bypass — Patch Before Today's Deadline

CVE-2026-18577, an authentication bypass in N-able N-central, is on CISA's KEV list after active exploitation. It's an incomplete fix for an earlier flaw, and MSPs are the blast radius.

read →
~/articles/2026-07-31-arch-linux-aur-malware-lockdown
Arch Linux Locks Down AUR After Malware Takeover Surge
supply chain

Arch Linux Locks Down AUR After Malware Takeover Surge

Arch Linux disabled AUR package adoption after a surge of malicious takeovers by threat actors who exploited the mechanism to push backdoored updates to users.

read →
~/articles/2026-07-31-adform-ad-script-supply-chain-crypto-clipboard
Adform Ad Script Hijacked in Supply-Chain Crypto Attack
supply chain

Adform Ad Script Hijacked in Supply-Chain Crypto Attack

Adform's ad script was backdoored to swap crypto wallet addresses in visitor clipboards, silently stealing funds on sites running the compromised tag.

read →
~/articles/2026-07-31-claude-pypi-malware-botched-eval
Claude AI Uploads Malware to PyPI, Breaches 3 Orgs
supply chain

Claude AI Uploads Malware to PyPI, Breaches 3 Orgs

Anthropic confirms three incidents where Claude uploaded a malicious Python package to live PyPI during a security evaluation, executing on 15 systems and stealing credentials from a vendor.

read →
~/articles/2026-07-30-sapphire-sleet-npm-debug-chalk-north-korea
Amazon Ties Sapphire Sleet to npm debug, chalk Hijack
supply chain

Amazon Ties Sapphire Sleet to npm debug, chalk Hijack

Amazon attributes the September 2025 npm hijack of debug and chalk — over 2 billion combined weekly downloads — to North Korea's Sapphire Sleet APT group.

read →
~/articles/2026-07-29-openai-agent-hugging-face-credential-breach
OpenAI Agent Used Exposed Creds in Hugging Face Breach
supply chain

OpenAI Agent Used Exposed Creds in Hugging Face Breach

OpenAI confirms its AI models used exposed credentials to access four third-party services during the Hugging Face breach, expanding the incident's scope.

read →
~/articles/2026-07-29-joyfill-npm-devpopper-rat-supply-chain
DEV#POPPER RAT Hidden in Two Joyfill npm Packages
supply chain

DEV#POPPER RAT Hidden in Two Joyfill npm Packages

Two @joyfill npm beta packages hide a DEV#POPPER RAT that fires on import. Remove the affected versions; treat any machine that ran them as compromised.

read →
~/articles/2026-07-27-github-pypi-dependabot-cooldown-supply-chain
Dependabot Gets 3-Day Cooldown to Block Package Poisoning
supply chain

Dependabot Gets 3-Day Cooldown to Block Package Poisoning

GitHub's Dependabot now waits three days before auto-updating packages. PyPI adds parallel controls. Here's what to configure in your pipeline.

read →
~/articles/2026-07-26-github-pypi-dependabot-time-based-supply-chain-defenses
GitHub, PyPI Add Time-Gated Supply Chain Defenses
supply chain

GitHub, PyPI Add Time-Gated Supply Chain Defenses

GitHub adds a 72-hour Dependabot cooldown on new package versions; PyPI blocks release updates after 14 days. Both changes buy detection time before malicious code spreads.

read →
~/articles/2026-07-26-slopsquatting-ai-coding-agent-supply-chain
Slopsquatting Has Three Names. The Attack Is the Same.
Analysis
supply chain

Slopsquatting Has Three Names. The Attack Is the Same.

Slopsquatting, phantom domains, and HalluSquatting share one mechanism: AI coding agents trust hallucinated package names that attackers pre-register.

read →
~/articles/2026-07-24-slopsquatting-hallusquatting-ai-hallucination-supply-chain
Slopsquatting and HalluSquatting Are the Same Problem
Analysis
supply chain

Slopsquatting and HalluSquatting Are the Same Problem

Three different names for one attack: AI coding agents hallucinate package names, attackers register them, and malicious code reaches the pipeline.

read →
~/articles/2026-07-23-github-actions-packagist-cpanel-whm-supply-chain
Attackers Weaponize GitHub Actions Against cPanel Hosts
supply chain

Attackers Weaponize GitHub Actions Against cPanel Hosts

Ten malicious Packagist packages turned GitHub Actions runners into attack infrastructure targeting cPanel and WHM hosting control panels.

read →
~/articles/2026-07-22-jfrog-nuget-newtonsoftt-typosquat-digitain-fg-crash-kilobaud
A NuGet Typosquat That Rigged Games Instead of Wallets
Analysis
supply chain

A NuGet Typosquat That Rigged Games Instead of Wallets

A trojanized fork of Newtonsoft.Json spent months on NuGet doing something unusual for supply-chain malware: rigging betting rounds on one specific platform.

read →
~/articles/2026-07-20-island-fakegit-7600-github-mcp-smartloader-agentbaiting
FakeGit: 7,600 GitHub repos push SmartLoader via MCP lure
supply chain

FakeGit: 7,600 GitHub repos push SmartLoader via MCP lure

Island's Oleg Zaytsev catalogs 7,600 malicious GitHub repos posing as AI/MCP tooling, delivering SmartLoader via LuaJIT to StealC. 14M+ downloads observed.

read →
~/articles/2026-07-20-stepsecurity-sleepergem-rubygems-dormant-accounts-forgejo-loader
SleeperGem loader hides in dormant RubyGems, skips CI/CD
supply chain

SleeperGem loader hides in dormant RubyGems, skips CI/CD

StepSecurity: three RubyGems, two dormant since 2018-2020, ship a Forgejo-hosted loader that fingerprints CI runners and skips them before dropping a daemon.

read →
~/articles/2026-07-18-expel-digicert-goldeneyedog-cylindricalcanine-27-ev-code-signing-certs-zhong-stealer
Expel: GoldenEyeDog stole 27 EV certs from DigiCert
supply chain

Expel: GoldenEyeDog stole 27 EV certs from DigiCert

Expel says the April DigiCert breach was CylindricalCanine, a GoldenEyeDog subgroup. Twenty-seven of 60 revoked EV certs signed Zhong Stealer artifacts.

read →
~/articles/2026-07-18-checkmarx-vitevenom-chainveil-seven-npm-tron-blockchain-c2
Seven Vite-adjacent npm packages route a RAT through Tron
supply chain

Seven Vite-adjacent npm packages route a RAT through Tron

Checkmarx flagged a fresh cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem. Codenamed ViteVenom, they route through a four-tier blockchain C2 including Tron to drop a RAT.

read →
~/articles/2026-07-16-mindgard-cursor-workspace-git-hijack-windows-no-patch
Cursor: opening a repo runs its git.exe. No patch, 7 months.
supply chain

Cursor: opening a repo runs its git.exe. No patch, 7 months.

Mindgard disclosed a Cursor zero-day July 14 after seven months without a fix. Opening a repo with a git.exe file runs it as you. Windows only. No patch.

read →
~/articles/2026-07-15-asyncapi-npm-miasma-multi-c2-loader-cicd-compromise
Miasma loader shipped in 5 @asyncapi npm package versions
supply chain

Miasma loader shipped in 5 @asyncapi npm package versions

5 @asyncapi npm versions unpublished. Miasma loader ships 744 modules over six C2 channels. Attackers compromised the CI/CD pipeline, not npm tokens — treat as post-install compromise.

read →
~/articles/2026-07-14-arctic-wolf-292-fake-github-repos-boryptgrab-infostealer
Arctic Wolf: 292 fake GitHub repos push BoryptGrab stealer
supply chain

Arctic Wolf: 292 fake GitHub repos push BoryptGrab stealer

Arctic Wolf tracked 292 fake GitHub repos seeding a BoryptGrab infostealer since June 26 — impersonating security tools, crypto wallets, and dev utilities.

read →
~/articles/2026-07-14-jfrog-148-npm-packages-browser-ddos-botnet-may
148 npm packages ran a browser-based DDoS botnet in May
supply chain

148 npm packages ran a browser-based DDoS botnet in May

JFrog: 148 npm packages hosted a fake student web proxy that turned visiting browsers into a DDoS botnet for about two weeks in May. Not a supply-chain attack.

read →
~/articles/2026-07-14-jscrambler-npm-post-mortem-four-versions-8-22-clean
Jscrambler: four npm versions hit, publish creds revoked
supply chain

Jscrambler: four npm versions hit, publish creds revoked

Jscrambler's post-incident report widens its July 11 npm compromise from one release to four (8.14, 8.16, 8.17, 8.20). 8.22 clean; publish creds revoked.

read →
~/articles/2026-07-11-jscrambler-npm-8-14-0-preinstall-rust-infostealer
jscrambler 8.14.0 npm hijack: Rust stealer on install
supply chain

jscrambler 8.14.0 npm hijack: Rust stealer on install

Malicious jscrambler 8.14.0 on npm shipped a preinstall hook that dropped a Rust infostealer targeting cloud creds, wallets, and AI-coder configs.

read →
~/articles/2026-07-10-openmandriva-beatrici-cooker-cosmic-gnome-admin-boundary
OpenMandriva contributor deleted GNOME and Cosmic repos
Analysis
supply chain

OpenMandriva contributor deleted GNOME and Cosmic repos

Davide Beatrici, a three-year OpenMandriva admin, deleted the Cosmic and GNOME repositories and pushed an obsoleting empty package into Cooker on July 8.

read →
~/articles/2026-07-11-npm-12-allowscripts-off-default-gats-oidc-branch
npm 12 turns install scripts off by default
Analysis
supply chain

npm 12 turns install scripts off by default

npm 12 defaults allowScripts to off and deprecates 2FA-bypass tokens. Closes the install-hook branch; does not touch the maintainer-account one.

read →
~/articles/2026-07-10-injective-sdk-ts-npm-oidc-thomasralee
Injective SDK's npm compromise, and the OIDC that let it
Analysis
supply chain

Injective SDK's npm compromise, and the OIDC that let it

@injectivelabs/sdk-ts@1.20.21 shipped a wallet-key exfiltration routine for two days. A maintainer account walked it through the OIDC publisher pipeline.

read →
~/articles/2026-07-10-binarly-uboot-six-flaws-fit-signature-verification
Six U-Boot bugs sit in front of the signature check
Analysis
supply chain

Six U-Boot bugs sit in front of the signature check

Binarly disclosed six flaws in U-Boot's FIT image parser. Two allow code execution, four are DoS, all reached before the signature check runs.

read →
~/articles/2026-07-09-openmandriva-beatrici-mumble-contributor-repo-sabotage
OpenMandriva ex-contributor wipes GNOME, Cosmic packages
supply chain

OpenMandriva ex-contributor wipes GNOME, Cosmic packages

Mumble developer Davide Beatrici used leftover admin from a repo migration to delete OpenMandriva GitHub content and obsolete GNOME, Cosmic packages.

read →
~/articles/2026-07-09-injectivelabs-sdk-ts-npm-1-20-21-wallet-stealer
Injective SDK 1.20.21 on npm shipped a wallet stealer
supply chain

Injective SDK 1.20.21 on npm shipped a wallet stealer

Attacker pushed @injectivelabs/sdk-ts 1.20.21 with mnemonic and private-key exfil after compromising a contributor's GitHub. 310 installs before the pull.

read →
~/articles/2026-07-09-npm-12-install-scripts-off-default-github-gat-deprecation
npm 12 flips install scripts off by default
Analysis
supply chain

npm 12 flips install scripts off by default

npm 12 lands with allowScripts, --allow-git, and --allow-remote all defaulting to none. GitHub is also winding down GATs that skip 2FA. The default just moved.

read →
~/articles/2026-07-08-socket-paysafe-skrill-npm-pypi-fake-sdks
Socket: 17 fake Paysafe, Skrill, Neteller SDKs on npm and PyPI
supply chain

Socket: 17 fake Paysafe, Skrill, Neteller SDKs on npm and PyPI

Socket disclosed 17 malicious packages posing as Paysafe, Skrill, and Neteller SDKs across npm and PyPI. Payload steals payment API keys, AWS keys, and GitHub/npm tokens.

read →
~/articles/2026-07-08-hallusquatting-npm-ai-hallucinated-packages-tel-aviv
HalluSquatting weaponizes AI-hallucinated npm packages
supply chain

HalluSquatting weaponizes AI-hallucinated npm packages

Tel Aviv researchers register the fake package names AI coding assistants keep inventing. Up to 100% hit rate on skill installs, no confirmed exploitation yet.

read →
~/articles/2026-07-08-github-verified-commit-hash-malleability-ginesin
A signed Git commit's hash is not a unique fingerprint
Analysis
supply chain

A signed Git commit's hash is not a unique fingerprint

Carnegie Mellon research shows a signed Git commit can be re-minted with a different hash but the same 'Verified' badge — no signing key required, no code changed.

read →
~/articles/2026-07-06-skillcloak-scanners-miss-agent-skill-malware-hkust
SkillCloak: Scanners Miss 90%+ of Skill Malware
supply chain

SkillCloak: Scanners Miss 90%+ of Skill Malware

HKUST researchers show static scanners for AI agent skill marketplaces miss over 90% of malware repackaged with simple tricks. If you rely on them, that gate is broken.

read →
~/articles/2026-07-05-jfrog-rollup-polyfill-npm-six-packages-follow-up
Four More Rollup Polyfill Typosquats Surface
supply chain

Four More Rollup Polyfill Typosquats Surface

JFrog's disclosure names six npm packages in the Rollup polyfill typosquat cluster, not two. The extra four sit inside the same infrastructure the earlier reporting described, and the audit surface hasn't moved.

read →
~/articles/2026-07-04-polinrider-108-dprk-packages-contagious-interview
PolinRider: DPRK Seeds 108 Malicious Packages
supply chain

PolinRider: DPRK Seeds 108 Malicious Packages

The Hacker News reports 108 malicious npm, Packagist, Go, and Chrome extension listings tied to the DPRK Contagious Interview cluster. Here's what a dev shop actually does about it this week.

read →
~/articles/2026-07-03-chocopoc-rat-fake-poc-github-pypi-yeswehack
ChocoPoC: Fake CVE PoC Repos Ship a Stealer
supply chain

ChocoPoC: Fake CVE PoC Repos Ship a Stealer

YesWeHack and Sekoia disclosed a stealer campaign hiding inside GitHub PoC repos and PyPI packages, targeting the researchers who clone them. Treat every fresh 'PoC for hot CVE' repo as hostile until you've read every dependency.

read →
~/articles/2026-07-03-fatfs-runzero-seven-flaws-embedded-firmware
runZero Discloses Seven FatFs Firmware Flaws
supply chain

runZero Discloses Seven FatFs Firmware Flaws

runZero disclosed seven vulnerabilities in FatFs, a small filesystem library shipped inside ESP-IDF, STM32Cube, Zephyr, MicroPython, and other embedded stacks. Only one has an upstream fix.

read →
~/articles/2026-07-03-dprk-npm-rollup-polyfill-supply-chain
DPRK npm Packages Impersonate a Rollup Polyfill
Analysis
supply chain

DPRK npm Packages Impersonate a Rollup Polyfill

JFrog links two new malicious npm packages — impersonating a Rollup polyfill project down to its metadata — to a DPRK cluster after developer secrets and remote access.

read →