#supplyChainAttack
A trojanized ad-tech script quietly swapped visitors' crypto wallet addresses in real time. https://intel.threadlinqs.com/threat/TL-2026-2656 #ThreatIntel #DoublePulsar #Adform #SupplyChainAttack
September 26, 2026 at 12:54 PM
Notepad++ Update Infrastructure Compromised

If you've updated Notepad++ recently, your system may be at serious risk. This isn't a drill.

#CyberSecurity #Malware #SupplyChainAttack #NotepadPlusPlus #SecurityAlert #Hacking #InfoSec
February 3, 2026 at 6:49 PM
Microsoft warns that Chinese cyber-espionage threat group 'Silk Typhoon' has shifted its tactics, now targeting remote management tools and cloud services in supply chain attacks that give them access to downstream customers. #supplychainattack #CyberAlerts www.bleepingcomputer.com/news/securit...
Silk Typhoon hackers now target IT supply chains to breach networks
Microsoft warns that Chinese cyber-espionage threat group 'Silk Typhoon' has shifted its tactics, now targeting remote management tools and cloud services in supply chain attacks that give them access...
www.bleepingcomputer.com
March 5, 2025 at 7:59 PM
Discovering the perfect #Java #SupplyChainAttack vector and how it got fixed
Discovering the perfect Java Supply Chain Attack vector and how it got fixed
xdev.software
November 20, 2024 at 11:28 AM
Deceptive Probes: Analyzing the tw-pkgprobe-7731 Malicious npm Campaign

An expert analysis of tw-pkgprobe-7731, a malicious npm package that impersonated Twilio bug bounty tools to steal developer credentials.

#npm #SupplyChainAttack

Read more →
Deceptive Probes: Analyzing the tw-pkgprobe-7731 Malicious npm Campaign
An expert analysis of tw-pkgprobe-7731, a malicious npm package that impersonated Twilio bug bounty tools to steal developer credentials.
calmvibez.com
September 23, 2026 at 11:38 AM
January 28, 2026 at 5:00 PM
Malicious npm packages are stealing SSH keys and API tokens from developers' systems. Vigilance is crucial. #CyberSecurity #npm #SupplyChainAttack #SSHKeys #APITokens #OpenSource thedailytechfeed.com/malicious-np...
June 12, 2026 at 6:47 PM
icymi yesterday, we identified a major malware #supplychainattack in #XRP

a backdoor was added to the official NPM package of XRP to steal private keys and send them to an attacker's C2 server 🗝️
April 23, 2025 at 5:17 PM
A malicious NPM package 'indexed-btree' got ~2M weekly downloads by hiding its payload in runtime code, bypassing security scans. It used Ethereum for C2 & earned its creator over €230k. #SupplyChainAttack #NPM #Malware #CyberSecurity

🌐 cyber[.]netsecops[.]io
Malicious
A malicious npm package,
cyber.netsecops.io
September 23, 2026 at 6:07 PM
Over 400 Arch Linux AUR packages compromised, deploying credential-stealing malware. #ArchLinux #AUR #Malware #CyberSecurity #Linux #SupplyChainAttack thedailytechfeed.com/over-400-arc...
June 13, 2026 at 3:46 AM
🚨 First-ever self-propagating #GlassWorm malware is targeting developers via the #OpenVSX marketplace, hijacking VSCode extensions, stealing credentials and using the #Solana blockchain for control. 🔐

Read: hackread.com/glassworm-ma...

#Cybersecurity #SupplyChainAttack #Malware #VSCode #Malware
GlassWorm Malware Targets Developers Through OpenVSX Marketplace
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
October 23, 2025 at 10:38 AM
Miasma malware turns trusted npm packages into persistent backdoors, highlighting urgent supply chain security needs. #Miasma #npm #SupplyChainAttack #CyberSecurity #Malware #DeveloperSecurity thedailytechfeed.com/miasma-malwa...
July 14, 2026 at 3:31 PM
Ransomware attack on Blue Yonder disrupts supply chains, impacting Starbucks & UK supermarkets. Highlights the critical need for cybersecurity in logistics.
#CyberSecurity #SupplyChainAttack
💻 Blue Yonder provides software solutions. The attack will impact the supply at ASDA and Sainsburys
December 5, 2024 at 9:16 AM
🪤 AI code suggestions sabotage software supply chain | The Register

#ai #aicode #vibecoding #supplychainattack #opensource
AI code suggestions sabotage software supply chain
: Hallucinated package names fuel 'slopsquatting'
www.theregister.com
April 28, 2025 at 9:20 PM
Amazon ties 2025 npm package hijacks to North Korean group, highlighting supply chain attack risks. #CyberSecurity #SupplyChainAttack #OpenSource #npm #NorthKorea #Amazon thedailytechfeed.com/amazon-links...
July 30, 2026 at 6:23 AM
148 npm packages turned browsers into a DDoS botnet, exposing new supply chain attack tactics. #CyberSecurity #DDoS #npm #SupplyChainAttack #OpenSource #Malware thedailytechfeed.com/malicious-np...
July 14, 2026 at 7:36 AM
Abandoned AWS S3 buckets could be the next big threat—hackers can repurpose them for supply-chain attacks that make SolarWinds look insignificant. Read more: www.theregister.com/2025/02/04/a... #AWS #CyberSecurity #SupplyChainAttack
Reused AWS S3 buckets a weak link in supply chain security
When cloud customers don't clean up after themselves, part 97
www.theregister.com
February 8, 2025 at 12:04 PM
Miasma worm compromises 73 Microsoft GitHub repositories, highlighting urgent need for supply chain security. #CyberSecurity #Microsoft #GitHub #MiasmaWorm #Azure #SupplyChainAttack thedailytechfeed.com/microsoft-gi...
June 10, 2026 at 1:05 PM
Hackers infiltrate open-source projects, releasing malicious updates to steal credentials and spread malware. #Cybersecurity #SupplyChainAttack #OpenSource #Malware #TechNews thedailytechfeed.com/hackers-comp...
May 19, 2026 at 4:15 PM
Supply chain attack hits 233 Laravel-Lang packages, injecting RCE backdoors. Immediate action required. #SupplyChainAttack #Laravel #Security #RCE #GitHub #CyberSecurity #DevOps thedailytechfeed.com/massive-supp...
May 23, 2026 at 6:00 AM
FBI warns of TeamPCP's attacks on developer tools, compromising open-source packages and stealing credentials. #CyberSecurity #TeamPCP #DeveloperTools #SupplyChainAttack #OpenSource #FBI #SoftwareSecurity thedailytechfeed.com/fbi-warns-of...
July 3, 2026 at 4:48 PM
Malicious npm packages are stealing SSH keys and API tokens from developers' systems. Vigilance is crucial. #PotatoSecurity #npm #SupplyChainAttack #SSHKeys #APITokens #OpenSource thedailytechfeed.com/malicious-np...
June 12, 2026 at 6:47 PM
Malicious npm packages target Alibaba developer tools, deploying a cross-platform RAT in a sophisticated supply chain attack. #CyberSecurity #SupplyChainAttack #npm #Alibaba #RAT thedailytechfeed.com/malicious-np...
August 3, 2026 at 7:13 PM