§Topic · Supply Chain Attacks
Supply Chain Attacks
Compromised packages, typosquatting campaigns, malicious dependencies, and software supply chain incidents on npm, PyPI, Go, and Rust.
All dispatches
Loading
§Topic · Supply Chain Attacks
Compromised packages, typosquatting campaigns, malicious dependencies, and software supply chain incidents on npm, PyPI, Go, and Rust.
All dispatchesAustralian authorities arrested two suspects tied to TeamPCP supply-chain attacks that tampered with open-source developer tools.
Trojanized npm packages install RedC2 4.0 Linux backdoor with AI-assisted command-and-control capabilities.
Supply-chain compromise of Android car head unit updater spreads malware to build ad-fraud and proxy botnet on vehicles.
Malicious Rust crate releases introduced build-time payloads, affecting widely used packages and prompting removals.
BdThemes supply-chain compromise poisoned JSON feeds to create rogue WordPress admin accounts, backdooring sites without modifying plugin files.
Ceva Logistics suffers supply-chain data breach, disrupting warehouse operations and impacting multiple European retail customers.
Analysis links TeamPCP to Redis attacks from 2020 and to later supply-chain campaigns via overlapping infrastructure and domains.
Campaign published nearly 800 malicious npm packages delivering a cross-platform RAT and infostealer for Windows, macOS and Linux.
ChainDrop npm worm compromised 400+ packages, impacting components with combined monthly installs exceeding two billion.
QuickFox supply-chain compromise trojanized Windows installer to deliver FDMTP backdoor in deployments since at least August 2025.
Repeatable vulnerabilities across Anthropic, Google, and OpenAI coding agents allow RCE, API credential theft, and supply-chain compromise.
Three high-severity Diffusers library flaws let crafted model repositories execute arbitrary code, bypassing trust_remote_code protections.
Mini Shai-Hulud/npm campaign compromises popular packages, indicating coordinated supply-chain poisoning activity.
ChainDrop poisoned 1,300+ npm packages, threatening developer supply chains and downstream applications.
Seven malicious Vite npm packages (ViteVenom) use blockchain-based C2 to deliver a RAT, compromising developer supply chains.
Ransomware forced Coca‑Cola's Fairlife to suspend U.S. production, impacting supply chains and operations.
Four @asyncapi npm packages were compromised to distribute a multi-stage botnet loader with credential-stealing payloads.
Cyberattack on Nichirei Logistics disrupted cold-chain operations, causing KFC and supermarket supply shortages across Japan.
Get these articles delivered to your inbox.
Subscribe free