Tagged: supply chain attack

Malicious npm worm AI attack diagram showing software supply chain infiltration and credential theft. 0

Malicious npm Worm Targets AI Software Supply Chains

Stealthy Infiltration Tactics A sophisticated new malware conceals itself within standard software development processes. Furthermore, it perfectly mimics legitimate automation tools. Security systems frequently overlook this hidden threat entirely. Meanwhile, the malicious program actively...

Diagram illustrating the jscrambler supply chain attack and IronWorm malware infection process 0

Jscrambler Supply Chain Attack Analysis

The Initial Compromise and Detection A stolen package registry key enabled a cybercriminal to execute a severe jscrambler supply chain attack. They successfully uploaded five infected versions of the npm package. These rogue versions...

PolinRider North Korea supply chain attack targeting npm, Go modules, and Chrome extensions 0

PolinRider Supply Chain Attack Spans npm, Go, Chrome

PolinRider is no longer a story about a handful of malicious npm packages. Researchers at Socket uncovered 162 malicious release artifacts spread across 108 packages and browser extensions. The campaign now reaches multiple open-source...

Klue OAuth breach diagram showing stolen OAuth tokens used to exfiltrate customer Salesforce data 0

Klue OAuth Breach Drives Salesforce Data Theft

The market intelligence platform Klue has confirmed a breach of part of its integration infrastructure. Attackers obtained OAuth tokens, the digital keys that grant access between services. With those keys, they slipped into the...

OptinMonster supply chain attack CDN compromise diagram showing backdoor plugin installation on WordPress admin accounts 0

OptinMonster Supply Chain Attack Hits 1.2M Sites

Popular WordPress plugins have found themselves at the center of a supply chain attack, where the products themselves were not compromised directly. Instead, attackers targeted the infrastructure responsible for distributing them. Three plugins from...

Miasma supply chain attack, GitHub malware toolkit, software supply chain security, npm package malware 0

Miasma Toolkit Targets Software Supply Chains

When a new batch of source code appeared on GitHub, it unexpectedly caught the attention of security researchers. Over the past few days, repositories bearing the name Miasma-Open-Source-Release began appearing across the platform in...