supply chain attack
38 stories on supply chain attack, newest first, from 39 briefings. Each is a plain-language summary written here for Australian business, with a link to the original reporting. Where several outlets covered the same event, the rest sit under it as extra coverage.
- Malicious Terraform Providers and Go Modules Used to Spread North Korea-Linked Malware
- Malicious npm and PyPI Packages Deliver Credential-Stealing Malware to Developers
- Fake 'Twilio Bug Bounty' npm Package Caught Stealing Developer Credentials
- CrowdSec's GitHub Data Stolen in Shai-Hulud Supply Chain Attack
- Malicious npm Package Skips Install Scripts, Hides Malware in Application Code Instead
- npm Supply Chain Attack Exploits 'Trusted Publishing' to Smuggle Hidden Malware Loader
- Fake Job Interviews Target Rust Developers to Spread Malware
- North Korean Hackers Target IT Developers With Fake Job Offers and macOS Backdoors
- Former Employee's Compromised Laptop Led to Leak of 170 CrowdSec Repositories
- 'Plugin4Shell' Flaw Lets Malicious Code Slip Past Version Locks in AI Coding Agents
- New 'WeaselBiscuit' Malware Found Hidden in 13 npm Packages Targeting Developers
- Zero-Click Flaw Puts AI Coding Agents at Risk of Full Takeover
- OpenAI Agents Linked to Malicious Package Flood on RubyGems
- AI Agent Swarm Linked to RubyGems Attack, Raising Alarm for Software Supply Chains
- Trezor Warns of Phishing Emails Sent Through Hacked Email Provider
- AI-Powered Attackers Are Now Stealing Credentials in Hours, Not Days
- KelpDAO Bridge Hack Drains $292M After Single Verifier Fails, Lazarus Group Suspected
- Google Warns AI Coding Tools Are Now a Top Target for Cybercriminals
- Weekly Threat Recap: Trusted Software Turned Malicious, Critical N-central Flaws Under Attack
- BGP Hijack Used to Push Malicious Update, Granting Attackers Root Access to Servers
- Hackers Hijack Internet Routing to Push Fake Virtualizor Update
- Malicious Packagist Packages Found Targeting Unpatched iPhones to Steal Crypto Wallet Data
- Two Australians Charged Over Alleged TeamPCP Supply Chain Hacking Attacks
- Two Australian Men Arrested Over 'TeamPCP' Software Supply Chain Attacks
- Two Alleged Members of 'TeamPCP' Hacking Group Arrested in Australia
- AI-Powered Backdoor Hidden in Fake npm Packages Targets Linux Systems
- Rust Supply Chain Attack Hits Solana Ecosystem, Opens Door to Remote Code Execution
- North Korean Hackers Linked to Malicious Rust Software Package
- Malicious Code Found in Popular Rust Software Libraries Used by Millions
- Fake RubyGems Packages Caught Stealing Browser Data and Crypto Wallets
- Supply Chain Attack on LiteLLM Hits Over 2,500 Organizations
- Brief but Dangerous: Malicious LiteLLM Package May Have Hit 2,100+ Organisations
- WordPress Plugin Vendor BdThemes Hit by Supply Chain Attack, Creating Rogue Admin Accounts
- Nearly 800 Fake npm Packages Caught Spreading Malware Across Windows, Mac and Linux
- Hackers Hide Malicious Server Addresses Inside Fake Ethereum Transactions
-
Massive Supply Chain Attack Hits Over 400 NPM Software Packages
Also covered by The Hacker News
- Supply Chain Attack Hits QuickFox VPN Users with Hidden Backdoor
- Malicious npm Packages Target Alibaba Developer Tool Users With Hidden Remote Access Trojan