Advertisement
LiteLLM PyPI Supply Chain Attack: TeamPCP Steals Credentials
TeamPCP compromised the LiteLLM PyPI package, backdooring it to steal credentials and auth tokens from hundreds of thousands of devices.
TeamPCP Backdoors LiteLLM 1.82.7–1.82.8 via CI/CD Compromise
TeamPCP threat actors compromised LiteLLM versions 1.82.7 and 1.82.8, deploying credential harvesters and Kubernetes lateral movement tools via CI/CD.
Malicious GitHub OpenClaw Deployer Repos Deliver Trojans
Analysts uncover an AI-assisted campaign using over 300 poisoned GitHub repositories like OpenClaw Deployer to distribute infostealers to developers.
npm Ghost Campaign: 7 Malicious Packages Steal Crypto Wallets
ReversingLabs uncovers the Ghost campaign targeting developers with 7 malicious npm packages designed to exfiltrate cryptocurrency wallets and credentials.
Trivy Supply Chain Attack Targets CI/CD Secrets in DevOps Workflows
A supply chain attack leveraged the Trivy security tool to deploy an infostealer within CI/CD pipelines, compromising cloud credentials and sensitive secrets.
CI/CD Pipeline Backdoors: Analyzing Recent Supply Chain Attacks
Exploration of supply chain risks in CI/CD pipelines, IoT device exploitation trends, and the security implications of government data acquisition.
Advertisement
Trivy Supply Chain Attack: Malicious Docker Hub Images Identified
Attackers hijacked Trivy Docker Hub images (v0.69.4-0.69.6) to distribute infostealers and Kubernetes wipers. Learn how to detect and remediate this threat.
Trivy Supply Chain Attack: TeamPCP Pushes Infostealer via GitHub
Threat actor TeamPCP compromised the Trivy-action repository to distribute infostealer malware through GitHub Actions, targeting CI/CD pipelines and secrets.
Trivy Supply Chain Attack Spreads CanisterWorm via 47 npm Packages
Attackers compromise 47 npm packages using CanisterWorm, a self-propagating threat leveraging ICP canisters following a major Trivy supply chain attack.
75 Trivy-Action GitHub Tags Hijacked in Supply Chain Attack
Attackers hijacked 75 tags in Aqua Security's Trivy GitHub Actions to exfiltrate CI/CD secrets, marking the second major breach in a single month.
GlassWorm Supply Chain Attack: 400+ Malicious Repos Identified
The GlassWorm campaign hits GitHub, npm, and VSCode marketplaces with over 400 malicious repositories. Learn to detect and mitigate this supply chain threat.
Tech Giants Pledge $12.5M to Bolster Open Source Software Security
Anthropic, AWS, Google, Microsoft, and OpenAI invest $12.5 million into the OpenSSF to mitigate systemic supply chain risks in open source ecosystems.
GlassWorm: Stolen GitHub Tokens Fuel Python Malware Injection
The GlassWorm campaign uses stolen GitHub tokens to inject malicious code into Python repositories, including Django and machine learning projects.
ForceMemo: Credential Theft Compromises Python Repositories
Researchers reveal ForceMemo, a campaign exploiting credentials stolen via GlassWorm to compromise hundreds of GitHub accounts and Python repositories.
AppsFlyer Web SDK Hijacked to Deliver Crypto-Stealing Malware
AppsFlyer's Web SDK was compromised in a supply chain attack to steal cryptocurrency. Learn how to detect and mitigate this JavaScript injection threat.
GlassWorm Abuses Open VSX Registry in Supply-Chain Attack
The GlassWorm campaign exploits transitive dependencies in 72 Open VSX extensions to deliver malicious loaders into developer environments.
Tag Poisoning Compromises Xygeni GitHub Action, C2 Implant Active
Attackers compromised the `xygeni/xygeni-action` GitHub Action using tag poisoning, deploying a C2 implant for up to a week. Users must verify integrity and review logs.
UNC6426 Exploits nx npm Supply-Chain Attack for AWS Admin Access
UNC6426 leveraged stolen GitHub tokens from the nx npm compromise to achieve full AWS administrative control and data exfiltration within 72 hours.
Malicious Rust Crates Steal Developer Secrets on Crates.io
Five malicious Rust crates on crates.io masquerade as time utilities to exfiltrate .env files, targeting developer environments and CI/CD pipelines.
F-35 Software Sovereignty and the Risks of System Jailbreaking
An analysis of the Dutch Defense Secretary's proposal to jailbreak F-35 software to ensure maintenance autonomy and the technical cybersecurity risks involved.
npm Malware @openclaw-ai/openclawai: macOS Credential Theft Alert
Security alert for @openclaw-ai/openclawai, a malicious npm package targeting macOS users to deploy remote access trojans and steal sensitive credentials.
Chrome Extensions QuickLens and BuildMelon Hijacked via Ownership Transfer
Attackers are exploiting Chrome extension ownership transfers to weaponize QuickLens and BuildMelon tools for code injection and data harvesting.
Over 100 GitHub Repositories Distributing BoryptGrab Stealer
A large-scale campaign on GitHub utilizes over 100 repositories to distribute BoryptGrab, an info-stealer targeting crypto wallets and browser data.
Malicious Laravel Packagist Packages Deploy Cross-Platform RAT
Security researchers discover malicious Laravel packages on Packagist delivering cross-platform RATs to Windows, macOS, and Linux systems. Audit your PHP dependencies.