An attacker accessed about 170 private CrowdSec GitHub repositories using stolen credentials from the May TanStack npm supply chain attack, exploiting a compromised former employee account.
Attackers compromised Brevo by stealing a Cloudflare API key and injecting malicious scripts into Brevo and its customers' websites, resulting in malware distribution via a supply-chain attack.
An attacker hijacked an AI coding assistant session to distribute the Shai-Hulud worm within approximately 100 internal code repositories at a SaaS provider, resulting in theft of repository secrets and source code.
Attackers breached Coder's Cloudflare infrastructure to push malicious Terraform modules that embed credential-stealing code, threatening developer credentials.
Attackers leveraged a BGP hijack to redirect Softaculous update traffic, delivering a malicious Virtualizor update that established persistent root access on five hypervisors.
Australian authorities arrested two men linked to the TeamPCP group known for extensive developer supply chain attacks, disrupting a significant threat actor.
Researchers identified 14 malicious npm packages that deploy RedC2 4.0, an AI-assisted Linux backdoor, leveraging open-source supply chain compromise for stealthy persistence.
Attackers compromised the maintainer account of the Rust crate arrayref to inject malware that executes on developer systems during compilation, risking exposure of sensitive data.
Two malicious LiteLLM packages on PyPI in March contained credential-stealing code that potentially exposed over 2,100 organizations by capturing cloud and system secrets.
The ChainDrop malware has compromised over 1,300 npm packages, impacting software supply chain security with billions of downloads monthly.
Adform's advertising scripts were compromised in a supply-chain attack that hijacks clipboard cryptocurrency addresses to redirect funds to attackers.
Amazon attributes multiple supply chain attacks on the Debug and Chalk npm packages to North Korean state-sponsored hackers, exposing risks to open-source software security.
The ShinyHunters extortion gang claimed responsibility for a data breach at Ernst & Young obtained through a supply-chain attack involving stolen system credentials.
An advanced threat actor exploits the update mechanism of ViPNet private networking software to attack Russian government agencies, illustrating ongoing espionage.
Seven malicious npm packages in the Vite ecosystem use a four-tier blockchain-based command-and-control infrastructure to deploy RAT malware, expanding the ChainVeil supply chain threat.
A malicious version of the Jscrambler npm package containing infostealer malware was published and downloaded nearly 1,500 times, posing risks to developers and users of this client-side security tool.
The jscrambler npm package version 8.14.0 was compromised to install a Rust-based infostealer via a preinstall hook, impacting Windows, macOS, and Linux environments.