Skip to main content
← All Articles

Category

Supply Chain

250 articles

Advertisement

HIGH
Supply Chain

LiteLLM PyPI Supply Chain Attack: TeamPCP Steals Credentials

TeamPCP compromised the LiteLLM PyPI package, backdooring it to steal credentials and auth tokens from hundreds of thousands of devices.

Runtime Rebel Intel
5 min read · Mar 25, 2026
TeamPCP Backdoors LiteLLM 1.82.7–1.82.8 via CI/CD Compromise
HIGH
Supply Chain

TeamPCP Backdoors LiteLLM 1.82.7–1.82.8 via CI/CD Compromise

TeamPCP threat actors compromised LiteLLM versions 1.82.7 and 1.82.8, deploying credential harvesters and Kubernetes lateral movement tools via CI/CD.

Runtime Rebel Intel
3 min read · Mar 24, 2026
Malicious GitHub OpenClaw Deployer Repos Deliver Trojans
HIGH
Supply Chain

Malicious GitHub OpenClaw Deployer Repos Deliver Trojans

Analysts uncover an AI-assisted campaign using over 300 poisoned GitHub repositories like OpenClaw Deployer to distribute infostealers to developers.

Runtime Rebel Intel
4 min read · Mar 24, 2026
npm Ghost Campaign: 7 Malicious Packages Steal Crypto Wallets
HIGH
Supply Chain

npm Ghost Campaign: 7 Malicious Packages Steal Crypto Wallets

ReversingLabs uncovers the Ghost campaign targeting developers with 7 malicious npm packages designed to exfiltrate cryptocurrency wallets and credentials.

Runtime Rebel Intel
3 min read · Mar 24, 2026
Trivy Supply Chain Attack Targets CI/CD Secrets in DevOps Workflows
HIGH
Supply Chain

Trivy Supply Chain Attack Targets CI/CD Secrets in DevOps Workflows

A supply chain attack leveraged the Trivy security tool to deploy an infostealer within CI/CD pipelines, compromising cloud credentials and sensitive secrets.

Runtime Rebel Intel
4 min read · Mar 24, 2026
CI/CD Pipeline Backdoors: Analyzing Recent Supply Chain Attacks
HIGH
Supply Chain

CI/CD Pipeline Backdoors: Analyzing Recent Supply Chain Attacks

Exploration of supply chain risks in CI/CD pipelines, IoT device exploitation trends, and the security implications of government data acquisition.

Runtime Rebel Intel
3 min read · Mar 23, 2026

Advertisement

Trivy Supply Chain Attack: Malicious Docker Hub Images Identified
HIGH
Supply Chain

Trivy Supply Chain Attack: Malicious Docker Hub Images Identified

Attackers hijacked Trivy Docker Hub images (v0.69.4-0.69.6) to distribute infostealers and Kubernetes wipers. Learn how to detect and remediate this threat.

Runtime Rebel Intel
4 min read · Mar 23, 2026
HIGH
Supply Chain

Trivy Supply Chain Attack: TeamPCP Pushes Infostealer via GitHub

Threat actor TeamPCP compromised the Trivy-action repository to distribute infostealer malware through GitHub Actions, targeting CI/CD pipelines and secrets.

Runtime Rebel Intel
3 min read · Mar 21, 2026
Trivy Supply Chain Attack Spreads CanisterWorm via 47 npm Packages
HIGH
Supply Chain

Trivy Supply Chain Attack Spreads CanisterWorm via 47 npm Packages

Attackers compromise 47 npm packages using CanisterWorm, a self-propagating threat leveraging ICP canisters following a major Trivy supply chain attack.

Runtime Rebel Intel
3 min read · Mar 21, 2026
75 Trivy-Action GitHub Tags Hijacked in Supply Chain Attack
HIGH
Supply Chain

75 Trivy-Action GitHub Tags Hijacked in Supply Chain Attack

Attackers hijacked 75 tags in Aqua Security's Trivy GitHub Actions to exfiltrate CI/CD secrets, marking the second major breach in a single month.

Runtime Rebel Intel
3 min read · Mar 20, 2026
HIGH
Supply Chain

GlassWorm Supply Chain Attack: 400+ Malicious Repos Identified

The GlassWorm campaign hits GitHub, npm, and VSCode marketplaces with over 400 malicious repositories. Learn to detect and mitigate this supply chain threat.

Runtime Rebel Intel
4 min read · Mar 18, 2026
INFO
Supply Chain

Tech Giants Pledge $12.5M to Bolster Open Source Software Security

Anthropic, AWS, Google, Microsoft, and OpenAI invest $12.5 million into the OpenSSF to mitigate systemic supply chain risks in open source ecosystems.

Runtime Rebel Intel
4 min read · Mar 17, 2026
GlassWorm: Stolen GitHub Tokens Fuel Python Malware Injection
HIGH
Supply Chain

GlassWorm: Stolen GitHub Tokens Fuel Python Malware Injection

The GlassWorm campaign uses stolen GitHub tokens to inject malicious code into Python repositories, including Django and machine learning projects.

Runtime Rebel Intel
3 min read · Mar 16, 2026
HIGH
Supply Chain

ForceMemo: Credential Theft Compromises Python Repositories

Researchers reveal ForceMemo, a campaign exploiting credentials stolen via GlassWorm to compromise hundreds of GitHub accounts and Python repositories.

Runtime Rebel Intel
3 min read · Mar 16, 2026
HIGH
Supply Chain

AppsFlyer Web SDK Hijacked to Deliver Crypto-Stealing Malware

AppsFlyer's Web SDK was compromised in a supply chain attack to steal cryptocurrency. Learn how to detect and mitigate this JavaScript injection threat.

Runtime Rebel Intel
3 min read · Mar 14, 2026
GlassWorm Abuses Open VSX Registry in Supply-Chain Attack
HIGH
Supply Chain

GlassWorm Abuses Open VSX Registry in Supply-Chain Attack

The GlassWorm campaign exploits transitive dependencies in 72 Open VSX extensions to deliver malicious loaders into developer environments.

Runtime Rebel Intel
3 min read · Mar 14, 2026
Tag Poisoning Compromises Xygeni GitHub Action, C2 Implant Active
HIGH
Supply Chain

Tag Poisoning Compromises Xygeni GitHub Action, C2 Implant Active

Attackers compromised the `xygeni/xygeni-action` GitHub Action using tag poisoning, deploying a C2 implant for up to a week. Users must verify integrity and review logs.

Runtime Rebel Intel
4 min read · Mar 12, 2026
UNC6426 Exploits nx npm Supply-Chain Attack for AWS Admin Access
HIGH
Supply Chain

UNC6426 Exploits nx npm Supply-Chain Attack for AWS Admin Access

UNC6426 leveraged stolen GitHub tokens from the nx npm compromise to achieve full AWS administrative control and data exfiltration within 72 hours.

Runtime Rebel Intel
3 min read · Mar 11, 2026
Malicious Rust Crates Steal Developer Secrets on Crates.io
HIGH
Supply Chain

Malicious Rust Crates Steal Developer Secrets on Crates.io

Five malicious Rust crates on crates.io masquerade as time utilities to exfiltrate .env files, targeting developer environments and CI/CD pipelines.

Runtime Rebel Intel
4 min read · Mar 11, 2026
INFO
Supply Chain

F-35 Software Sovereignty and the Risks of System Jailbreaking

An analysis of the Dutch Defense Secretary's proposal to jailbreak F-35 software to ensure maintenance autonomy and the technical cybersecurity risks involved.

Runtime Rebel Intel
3 min read · Mar 10, 2026
npm Malware @openclaw-ai/openclawai: macOS Credential Theft Alert
HIGH
Supply Chain

npm Malware @openclaw-ai/openclawai: macOS Credential Theft Alert

Security alert for @openclaw-ai/openclawai, a malicious npm package targeting macOS users to deploy remote access trojans and steal sensitive credentials.

Runtime Rebel Intel
4 min read · Mar 9, 2026
Chrome Extensions QuickLens and BuildMelon Hijacked via Ownership Transfer
HIGH
Supply Chain

Chrome Extensions QuickLens and BuildMelon Hijacked via Ownership Transfer

Attackers are exploiting Chrome extension ownership transfers to weaponize QuickLens and BuildMelon tools for code injection and data harvesting.

Runtime Rebel Intel
4 min read · Mar 9, 2026
HIGH
Supply Chain

Over 100 GitHub Repositories Distributing BoryptGrab Stealer

A large-scale campaign on GitHub utilizes over 100 repositories to distribute BoryptGrab, an info-stealer targeting crypto wallets and browser data.

Runtime Rebel Intel
4 min read · Mar 7, 2026
Malicious Laravel Packagist Packages Deploy Cross-Platform RAT
HIGH
Supply Chain

Malicious Laravel Packagist Packages Deploy Cross-Platform RAT

Security researchers discover malicious Laravel packages on Packagist delivering cross-platform RATs to Windows, macOS, and Linux systems. Audit your PHP dependencies.

Runtime Rebel Intel
3 min read · Mar 4, 2026