Tagged: supply chain attack
Stealthy Infiltration Tactics A sophisticated new malware conceals itself within standard software development processes. Furthermore, it perfectly mimics legitimate automation tools. Security systems frequently overlook this hidden threat entirely. Meanwhile, the malicious program actively...
The Initial Compromise and Detection A stolen package registry key enabled a cybercriminal to execute a severe jscrambler supply chain attack. They successfully uploaded five infected versions of the npm package. These rogue versions...
An ordinary cryptocurrency wallet library update quickly transformed into a devastating trap. Within just 49 minutes, this trap could hand attackers complete control over user funds. Specifically, malicious actors embedded a malicious code payload...
PolinRider is no longer a story about a handful of malicious npm packages. Researchers at Socket uncovered 162 malicious release artifacts spread across 108 packages and browser extensions. The campaign now reaches multiple open-source...
A digital signature should prove that an Android app truly comes from its original developer. New research shows how a single leaked signing key can turn that trust mechanism into a supply-chain weakness. According...
Attackers infected more than 140 packages from the Mastra AI ecosystem through npm. The malicious code ran right after npm install or npm update. So the infection could reach developer workstations and build servers,...
Attackers injected malicious JavaScript into Okendo Reviews, a product review widget used by more than 18,000 brands. The compromised script loaded on store pages. After a few checks, it could show visitors a fake...
The longer an electronics supply chain grows, the harder it gets to keep trade secrets inside factory walls. India’s Tata Electronics has now confirmed a recent cyber incident. The confirmation followed reports that files...
GitHub has filled up with fake repositories. They disguise themselves as ordinary developer projects. In reality, they push Trojans through links to ZIP archives. A developer using the alias Orchid uncovered the large campaign....
The market intelligence platform Klue has confirmed a breach of part of its integration infrastructure. Attackers obtained OAuth tokens, the digital keys that grant access between services. With those keys, they slipped into the...
Popular WordPress plugins have found themselves at the center of a supply chain attack, where the products themselves were not compromised directly. Instead, attackers targeted the infrastructure responsible for distributing them. Three plugins from...
When a new batch of source code appeared on GitHub, it unexpectedly caught the attention of security researchers. Over the past few days, repositories bearing the name Miasma-Open-Source-Release began appearing across the platform in...