Tag: Supply Chain Attack

SvcHostUpdate.exe in Startup: The MythicalsGames Backdoor

SvcHostUpdate.exe in Windows Startup matches a malicious web3-token-helper chain. Learn what the…

Brendan Smith

Joyfill npm Packages Compromised: Six Malicious Versions

Six prerelease versions of @joyfill/components and @joyfill/layouts carried an import-time RAT and…

Brendan Smith

Jscrambler npm Package Compromised: Check Five Malicious Versions

Five malicious Jscrambler npm releases ran a cross-platform infostealer. Check versions, lockfiles,…

Brendan Smith

OptinMonster CDN Backdoor Checks

WordPress sites using OptinMonster, TrustPulse, or PushEngage should check for rogue admin…

Brendan Smith

TrapDoor Hits npm, PyPI and Crates.io With AI Config Poisoning

TrapDoor spreads malicious packages through npm, PyPI and Crates.io, steals developer secrets,…

Stephanie Adlam

Packagist Postinstall Malware: What Developers Should Check

A Packagist and GitHub supply-chain campaign used malicious postinstall hooks to fetch…

Stephanie Adlam

Laravel-Lang Composer Packages Rewritten to Steal CI Secrets

Laravel-Lang Composer packages were compromised through rewritten tags that run a PHP…

Stephanie Adlam

Grafana Says Missed Token Let Attackers Copy Private Repos

Grafana says attackers copied two private GitHub repositories after one workflow token…

Stephanie Adlam

GitHub Internal Repos Exposed Through Poisoned VS Code Extension

GitHub says an employee device was compromised through a poisoned VS Code…

Stephanie Adlam

Shai-Hulud AntV npm Supply-Chain Wave: What Developers Should Check

Shai-Hulud returned in an AntV npm supply-chain wave affecting hundreds of packages.…

Stephanie Adlam

node-ipc npm Package Compromised With Credential Stealer

Malicious node-ipc versions 9.1.6, 9.2.3, and 12.0.1 were published to npm with…

Stephanie Adlam

RubyGems Pauses Signups After Malicious Package Attack

RubyGems disabled new account registration after reports of hundreds of malicious packages,…

Stephanie Adlam

AI Assistant

Hello! 👋 How can I help you today?