Tagged: supply chain attack

Shai-Hulud npm worm architecture and JavaScript supply chain attack payload 0

Shai-Hulud npm Worm Compromises Supply Chain

The Initial JavaScript Breach A single installation of a routine JavaScript library could expose a company’s cloud infrastructure, repositories, and internal services to attackers. The Shai-Hulud npm worm infiltrated highly popular packages. Users download...

SANDWORM_MODE worm attack diagram illustrating AI toolchain supply chain compromise 0

SANDWORM_MODE Worm Exploits AI Toolchains and Supply Chains

The Emergence of AI Infrastructure Worms Malicious packages have evolved to inconspicuously masquerade as routine operations executed by artificial intelligence assistants and automated build systems. The pervasive SANDWORM_MODE worm systematically exfiltrates cryptographic keys, infects...

Malicious npm worm AI attack diagram showing software supply chain infiltration and credential theft. 0

Malicious npm Worm Targets AI Software Supply Chains

Stealthy Infiltration Tactics A sophisticated new malware conceals itself within standard software development processes. Furthermore, it perfectly mimics legitimate automation tools. Security systems frequently overlook this hidden threat entirely. Meanwhile, the malicious program actively...

Diagram illustrating the jscrambler supply chain attack and IronWorm malware infection process 0

Jscrambler Supply Chain Attack Analysis

The Initial Compromise and Detection A stolen package registry key enabled a cybercriminal to execute a severe jscrambler supply chain attack. They successfully uploaded five infected versions of the npm package. These rogue versions...

PolinRider North Korea supply chain attack targeting npm, Go modules, and Chrome extensions 0

PolinRider Supply Chain Attack Spans npm, Go, Chrome

PolinRider is no longer a story about a handful of malicious npm packages. Researchers at Socket uncovered 162 malicious release artifacts spread across 108 packages and browser extensions. The campaign now reaches multiple open-source...