Tag: Supply Chain Attack

Virtualizor BGP Hijack: Check the Server After the Update

A valid certificate accompanied a malicious Virtualizor update. Check the vendor indicator,…

Stephanie Adlam

Packagist iPhone Spyware: Check iOS and the Website Theme

Malicious Packagist themes target older iPhones through streaming sites. Separate phone updates,…

Brendan Smith

RedC2 npm Packages: Importing Can Infect a Linux Host

RedC2 starts a Linux backdoor when a poisoned npm package is imported.…

Brendan Smith

arrayref 0.3.10 Malware: Check Rust Builds and CI

Three poisoned Rust crates ran a malicious dependency during builds. Check lockfiles,…

Brendan Smith

LiteLLM Breach May Have Exposed 2,500+ Organizations

CloudSEK maps 2,500+ organizations in a LiteLLM exposure dataset. Check versions 1.82.7…

Brendan Smith

BdThemes Plugins Installed Backdoors Through a Poisoned API

Seven BdThemes WordPress plugins loaded a poisoned remote feed that created rogue…

Brendan Smith

Solidity Pro VS Code Extensions Steal Wallets and API Keys

Malicious Solidity Pro extensions stole wallet data, API keys, SSH keys, and…

Brendan Smith

NUL1DROPPER npm Malware Runs When a Package Is Imported

NUL1DROPPER runs when poisoned npm packages are imported, not through install scripts.…

Brendan Smith

QuickFox VPN Malware Installed the FDMTP Backdoor

QuickFox Windows installers delivered the FDMTP backdoor. Check affected versions, local indicators,…

Brendan Smith

Keyv npm Worm Poisoned 444 Packages: Check Before Rotating Tokens

The Keyv npm worm poisoned hundreds of packages and can react when…

Brendan Smith

Arch Freezes AUR Pushes After Malware Wave: Check Your System

Arch temporarily stopped AUR pushes after malicious package takeovers. Check openconnect-sso exposure,…

Brendan Smith

Adform Script Swapped Crypto Wallet Addresses on Websites

A compromised Adform tracking script could replace Bitcoin, Ethereum, and Tron recipient…

Brendan Smith

AI Assistant

Hello! 👋 How can I help you today?