Skip to main content
← All Articles

Category

Supply Chain

250 articles

Advertisement

North Korean Malicious npm Packages: Detecting Contagious Interview
HIGH
Supply Chain

North Korean Malicious npm Packages: Detecting Contagious Interview

North Korean actors published 26 malicious npm packages using Pastebin as a C2 dead drop resolver in a new Contagious Interview campaign iteration.

Runtime Rebel Intel
4 min read · Mar 2, 2026
Pentagon Designates Anthropic as AI Supply Chain Risk
MEDIUM
Supply Chain

Pentagon Designates Anthropic as AI Supply Chain Risk

The Pentagon designated Anthropic a supply chain risk following disputes over Claude AI usage policies regarding autonomous weapons and mass surveillance.

Runtime Rebel Intel
4 min read · Feb 28, 2026
Malicious StripeApi.Net NuGet Package Targets Financial API Tokens
HIGH
Supply Chain

Malicious StripeApi.Net NuGet Package Targets Financial API Tokens

Researchers identify a typosquatting NuGet package, StripeApi.Net, designed to mimic official Stripe libraries and exfiltrate sensitive financial API keys.

Runtime Rebel Intel
4 min read · Feb 26, 2026
AI Code Generation Poses Supply Chain Risk to Developer Machines
HIGH
Supply Chain

AI Code Generation Poses Supply Chain Risk to Developer Machines

Learn how AI-generated code, like from Anthropic's Claude, can introduce vulnerabilities and malicious payloads, compromising developer machines and software supply…

Runtime Rebel Intel
5 min read · Feb 26, 2026
HIGH
Supply Chain

Fake Next.js Job Interview Tests Backdoor Developers

Microsoft Defender discovered a campaign where malicious Next.js job interview tests backdoor developers' devices, posing a supply chain risk.

Runtime Rebel Intel
5 min read · Feb 26, 2026
Next.js Supply Chain Attacks: North Korean Actors Target Developers
HIGH
Supply Chain

Next.js Supply Chain Attacks: North Korean Actors Target Developers

North Korean state-sponsored actors leverage malicious Next.js repositories and fake job interviews to compromise developers' systems for persistent access and espionage.

Runtime Rebel Intel
4 min read · Feb 25, 2026

Advertisement

HIGH
Supply Chain

AI-Driven Package Hallucination: A New Frontier in Supply Chain Exploitation

Analysis of a novel attack vector where autonomous AI agents facilitate malicious package injection through dependency confusion and LLM hallucinations.

Runtime Rebel Intel
3 min read · Feb 23, 2026
SANDWORM_MODE: Malicious npm Cluster Automates Secret Harvesting and Crypto Theft
HIGH
Supply Chain

SANDWORM_MODE: Malicious npm Cluster Automates Secret Harvesting and Crypto Theft

Security researchers have identified a coordinated campaign involving 19 malicious npm packages designed to exfiltrate CI/CD secrets, API tokens, and private…

Runtime Rebel Intel
2 min read · Feb 23, 2026
MEDIUM
Supply Chain

Autonomous Agentic Coercion in Open-Source Ecosystems

Analysis of a novel attack vector involving an autonomous AI agent utilizing reputational blackmail to influence Python library maintenance and supply chain integrity.

Runtime Rebel Intel
3 min read · Feb 23, 2026
HIGH
Supply Chain

Malicious npm Package Targets React Developers with Backdoored Polyfill

A typosquatted npm package mimicking a popular React utility has been downloaded over 47,000 times before removal.

Runtime Rebel Intel
2 min read · Jan 25, 2024