Skip to main content
← All Articles

Category

Supply Chain

232 articles

Advertisement

Klue Security Incident: Analyzing Third-Party Supply Chain Impact
MEDIUM
Supply Chain

Klue Security Incident: Analyzing Third-Party Supply Chain Impact

An analysis of the Klue security incident affecting Recorded Future, highlighting the risks of third-party SaaS vendors and competitive intelligence data.

Runtime Rebel Intel
3 min read · Jul 14, 2026
SU
HIGH
Supply Chain

Jscrambler npm Package Backdoored with Infostealer Malware

A malicious version of the Jscrambler npm package, 5.0.0-beta-1, was backdoored with infostealer malware, affecting 1,500 downloads. Immediate action needed.

Runtime Rebel Intel
4 min read · Jul 13, 2026
ModHeader Extension Pulled Over Dormant Browsing Data Collector
MEDIUM
Supply Chain

ModHeader Extension Pulled Over Dormant Browsing Data Collector

ModHeader, a popular browser extension with 1.6M installs on Chrome and Edge, was pulled by Google and Microsoft after a dormant browsing history collector was found.

Runtime Rebel Intel
4 min read · Jul 13, 2026
SU
HIGH
Supply Chain

Lidl Data Breach: Service Provider Hack Exposes Customer Info

Lidl notifies customers in Germany, Belgium, and Netherlands after a third-party service provider breach exposed personal data and order histories.

Runtime Rebel Intel
4 min read · Jul 13, 2026
jscrambler 8.14.0 Compromised: Rust Infostealer Supply Chain Attack
HIGH
Supply Chain

jscrambler 8.14.0 Compromised: Rust Infostealer Supply Chain Attack

The jscrambler 8.14.0 npm release was compromised with a malicious preinstall hook dropping a cross-platform Rust infostealer. Mitigate the threat now.

Runtime Rebel Intel
4 min read · Jul 11, 2026
Injective Labs npm Package Compromise Steals Crypto Keys
HIGH
Supply Chain

Injective Labs npm Package Compromise Steals Crypto Keys

Critical supply chain attack compromises Injective Labs SDK on GitHub, distributing malicious npm package `@injectivelabs/sdk-ts@1.20.21` to steal crypto wallet keys.

Runtime Rebel Intel
4 min read · Jul 10, 2026
SU
HIGH
Supply Chain

Injective SDK npm Compromise: Crypto Wallet Stealer Detected

A malicious version of the Injective SDK (injective-js) on npm was published via a GitHub compromise, deploying a crypto wallet stealer. Developers are at risk.

Runtime Rebel Intel
4 min read · Jul 10, 2026
SU
MEDIUM
Supply Chain

OpenMandriva Insider Sabotage: Risks of Contributor Access Misuse

OpenMandriva Linux reports an attempted internal sabotage by a disgruntled contributor, highlighting critical risks of insider threats in open-source projects.

Runtime Rebel Intel
4 min read · Jul 10, 2026
npm 12 Enhances Supply Chain Security by Disabling Install Scripts
INFO
Supply Chain

npm 12 Enhances Supply Chain Security by Disabling Install Scripts

npm version 12 introduces critical security defaults, disabling install scripts and deprecating GATs, significantly mitigating JavaScript supply chain risks.

Runtime Rebel Intel
4 min read · Jul 9, 2026
SU
HIGH
Supply Chain

Fake Paysafe/Skrill SDKs on npm & PyPI Steal Credentials

Malicious packages impersonating Paysafe and Skrill SDKs on npm and PyPI platforms are stealing credentials from developers and users. Threat intelligence analysis.

Runtime Rebel Intel
4 min read · Jul 8, 2026
SU
HIGH
Supply Chain

GitHub Actions Attack Patterns Evade CI Security Scanners

Learn how sophisticated GitHub Actions attack patterns bypass traditional CI security scanners, exposing CI/CD pipelines to supply chain risks. Understand the threats…

Runtime Rebel Intel
4 min read · Jul 7, 2026
PolinRider: North Korean Hackers Push 108 Malicious Packages
HIGH
Supply Chain

PolinRider: North Korean Hackers Push 108 Malicious Packages

Analysis of the PolinRider campaign where North Korean actors published 108 malicious packages and extensions across npm, Go, and Chrome ecosystems.

Runtime Rebel Intel
4 min read · Jul 4, 2026
N. Korea-Linked npm Packages Mimic Rollup Polyfills for Data Theft
HIGH
Supply Chain

N. Korea-Linked npm Packages Mimic Rollup Polyfills for Data Theft

North Korea-linked actors use malicious npm packages ('rollup-packages-polyfill-core', 'rollup-runtime-polyfill-core') to steal developer secrets, mimicking Rollup…

Runtime Rebel Intel
5 min read · Jul 3, 2026
SU
INFO
Supply Chain

Auditing AI-Driven Software Development: Security Governance Strategies

Learn how to audit AI-generated code and govern AI tool usage to mitigate security risks in modern software development lifecycles.

Runtime Rebel Intel
3 min read · Jul 3, 2026
SU
INFO
Supply Chain

Windows 11 Emoji Panel GIF Fix Highlights Supply Chain Dependency

Microsoft resolves Windows 11 Emoji Panel GIF functionality after provider shutdown, underscoring third-party service dependencies in OS features.

Runtime Rebel Intel
4 min read · Jul 1, 2026
Education Sector Third-Party Risk: Protecting Student Data
HIGH
Supply Chain

Education Sector Third-Party Risk: Protecting Student Data

The education sector confronts growing third-party breach threats, endangering student data. This article details vendor risk mitigation strategies against ransomware…

Runtime Rebel Intel
4 min read · Jun 27, 2026
SU
INFO
Supply Chain

Linux Foundation's Project Akrites: Bolstering Open Source Security

Project Akrites aims to streamline vulnerability management across open source projects, enhancing reporting, patching, and disclosure processes for critical software.

Runtime Rebel Intel
4 min read · Jun 26, 2026
Cordyceps CI/CD Flaws: Supply Chain Attacks on GitHub Repositories
HIGH
Supply Chain

Cordyceps CI/CD Flaws: Supply Chain Attacks on GitHub Repositories

Novee Security uncovered Cordyceps, a critical CI/CD workflow flaw exposing over 300 GitHub repositories to supply chain compromise, affecting major organizations.

Runtime Rebel Intel
4 min read · Jun 24, 2026
Cordyceps: Defending Against Malicious Pull Requests in CI/CD
HIGH
Supply Chain

Cordyceps: Defending Against Malicious Pull Requests in CI/CD

The Cordyceps campaign highlights critical CI/CD vulnerabilities in GitHub Actions, targeting high-profile projects like Apache Doris and Cloudflare Workers SDK.

Runtime Rebel Intel
4 min read · Jun 24, 2026
OAuth Token Theft: How Icarus Targets Salesforce via Klue Breach
HIGH
Supply Chain

OAuth Token Theft: How Icarus Targets Salesforce via Klue Breach

Attackers known as Icarus are exploiting compromised OAuth tokens from Klue to exfiltrate sensitive Salesforce data. Learn how to mitigate supply chain risks.

Runtime Rebel Intel
4 min read · Jun 24, 2026
Malicious npm Packages Impersonate PostCSS to Deliver Windows RAT
HIGH
Supply Chain

Malicious npm Packages Impersonate PostCSS to Deliver Windows RAT

Security researchers uncover malicious npm packages such as postcss-minify-selector-parser delivering Windows RATs via supply chain attacks. Audit your builds.

Runtime Rebel Intel
3 min read · Jun 23, 2026
ShapedPlugin Supply Chain Attack: WordPress Pro Plugins Backdoored
HIGH
Supply Chain

ShapedPlugin Supply Chain Attack: WordPress Pro Plugins Backdoored

Attackers compromised ShapedPlugin's distribution pipeline to inject backdoors into Pro WordPress plugins. Learn how to detect and remediate this supply chain threat.

Runtime Rebel Intel
4 min read · Jun 23, 2026
SU
HIGH
Supply Chain

North Korean Sapphire Sleet Compromises 140+ Mastra AI npm Packages

Microsoft attributes the Mastra AI supply chain attack to Sapphire Sleet (BlueNoroff), involving 140+ malicious npm packages targeting AI developers.

Runtime Rebel Intel
3 min read · Jun 20, 2026
Klue Security Incident: Mitigating Third-Party Risk in Intelligence
MEDIUM
Supply Chain

Klue Security Incident: Mitigating Third-Party Risk in Intelligence

Analyze the impact of the Klue security incident on Recorded Future. Learn how to secure SaaS integrations and improve third-party vendor risk management.

Runtime Rebel Intel
3 min read · Jun 19, 2026