Skip to main content
← All Articles

Category

Supply Chain

232 articles

Advertisement

Miasma Supply Chain Attack: Defending Red Hat npm Environments
HIGH
Supply Chain

Miasma Supply Chain Attack: Defending Red Hat npm Environments

Analysis of the Miasma supply chain attack targeting Red Hat npm packages with credential-stealing worms. Technical details and mitigation guide for SOC teams.

Runtime Rebel Intel
3 min read · Jun 1, 2026
Malicious npm Package Targets Claude AI User Data — Technical Analysis
HIGH
Supply Chain

Malicious npm Package Targets Claude AI User Data — Technical Analysis

Researchers discover mouse5212-super-formatter, a malicious npm package designed to exfiltrate sensitive files from Claude AI user directories.

Runtime Rebel Intel
3 min read · May 27, 2026
SU
INFO
Supply Chain

RevEng.AI Secures $15M for AI-Powered Software Binary Analysis

RevEng.AI raises $15 million to scale BinNet, a proprietary AI model designed to automate binary analysis and detect hidden backdoors in software assets.

Runtime Rebel Intel
4 min read · May 27, 2026
GlassWorm Malware Takedown: Disruption of Developer Supply Chain C2
HIGH
Supply Chain

GlassWorm Malware Takedown: Disruption of Developer Supply Chain C2

CrowdStrike, Google, and Shadowserver disrupt the GlassWorm malware C2 infrastructure, halting a persistent developer-focused supply chain attack campaign.

Runtime Rebel Intel
4 min read · May 27, 2026
Shai-Hulud Campaign: TeamPCP Targets Open-Source Supply Chain
HIGH
Supply Chain

Shai-Hulud Campaign: TeamPCP Targets Open-Source Supply Chain

Analysis of the Shai-Hulud campaign by TeamPCP, detailing their open-source supply chain attacks, TTPs, and critical mitigation strategies.

Runtime Rebel Intel
5 min read · May 26, 2026
Megalodon Malware: GitHub Repo Compromise & Secret Theft
HIGH
Supply Chain

Megalodon Malware: GitHub Repo Compromise & Secret Theft

Analysis of the Megalodon malware campaign, which compromised over 5,500 GitHub repositories in six hours to steal developer credentials and sensitive secrets. Learn how…

Runtime Rebel Intel
4 min read · May 26, 2026
SU
HIGH
Supply Chain

TeamPCP Supply Chain Attack Targets Microsoft SDKs and GitHub

TeamPCP expands its supply chain campaign to trojanize official Microsoft Python SDKs and infiltrate GitHub, requiring immediate dependency audits.

Runtime Rebel Intel
3 min read · May 25, 2026
SU
HIGH
Supply Chain

Megalodon Supply Chain Attack Infects 5,500+ GitHub Repositories

Attackers used automated commits to inject malicious GitHub Actions workflows into 5,500+ repositories, targeting CI/CD secrets and sensitive tokens.

Runtime Rebel Intel
4 min read · May 25, 2026
TrapDoor Campaign: Detecting Cross-Ecosystem Supply Chain Attacks
HIGH
Supply Chain

TrapDoor Campaign: Detecting Cross-Ecosystem Supply Chain Attacks

The TrapDoor campaign targets npm, PyPI, and Crates.io with over 384 malicious versions designed to exfiltrate developer credentials and sensitive data.

Runtime Rebel Intel
4 min read · May 25, 2026
SU
HIGH
Supply Chain

Laravel Lang Hijack: Supply Chain Attack via Malicious GitHub Tags

Analysis of the Laravel Lang supply chain attack involving malicious GitHub tags v13.8.1 and v13.8.2 used to steal environmental secrets and credentials.

Runtime Rebel Intel
4 min read · May 24, 2026
Packagist Supply Chain Attack: 8 Packages Deliver Linux Malware
HIGH
Supply Chain

Packagist Supply Chain Attack: 8 Packages Deliver Linux Malware

Security researchers identified a supply chain attack on Packagist involving eight infected packages that deploy Linux malware via GitHub Releases URLs.

Runtime Rebel Intel
3 min read · May 23, 2026
npm Staged Publishing: New 2FA Controls Prevent Supply Chain Attacks
MEDIUM
Supply Chain

npm Staged Publishing: New 2FA Controls Prevent Supply Chain Attacks

GitHub introduces staged publishing for npm, requiring manual 2FA approval for package releases to mitigate malicious automated updates and account takeovers.

Runtime Rebel Intel
4 min read · May 23, 2026
Laravel-Lang PHP Packages Compromised: Credential Stealer Alert
HIGH
Supply Chain

Laravel-Lang PHP Packages Compromised: Credential Stealer Alert

Multiple Laravel-Lang PHP packages have been compromised to deliver a cross-platform credential stealer. Learn how to detect and mitigate this supply chain threat.

Runtime Rebel Intel
4 min read · May 23, 2026
Megalodon Campaign: 5,561 GitHub Repos Hit by Malicious Workflows
HIGH
Supply Chain

Megalodon Campaign: 5,561 GitHub Repos Hit by Malicious Workflows

Automated Megalodon attack pushes 5,718 malicious commits to GitHub repositories to exfiltrate secrets via GitHub Actions workflows.

Runtime Rebel Intel
4 min read · May 22, 2026
SU
MEDIUM
Supply Chain

Grafana Codebase Stolen via TanStack Supply Chain Attack

Grafana confirms unauthorized access to private GitHub repositories after a developer token leaked in the TanStack breach was not rotated.

Runtime Rebel Intel
3 min read · May 22, 2026
Securing Agentic AI Workflows with Advanced AI BOM Frameworks
MEDIUM
Supply Chain

Securing Agentic AI Workflows with Advanced AI BOM Frameworks

Learn why CISOs must transition from traditional SBOMs to Agentic-Ready AI BOMs to manage risks in autonomous AI systems and data supply chains.

Runtime Rebel Intel
3 min read · May 22, 2026
SU
HIGH
Supply Chain

Software Supply Chain Security: Addressing Visibility Gaps

An analysis of the growing software supply chain crisis, focusing on the acceleration of vulnerability exploitation and the lack of systemic visibility.

Runtime Rebel Intel
3 min read · May 21, 2026
SU
HIGH
Supply Chain

GitHub Repository Breach Linked to TanStack Supply Chain Attack

GitHub confirms the breach of 3,800 internal repositories via a compromised VS Code extension linked to the TanStack npm supply chain attack.

Runtime Rebel Intel
4 min read · May 21, 2026
GitHub Internal Repositories Breached via Nx Console VS Code Extension
MEDIUM
Supply Chain

GitHub Internal Repositories Breached via Nx Console VS Code Extension

GitHub confirms internal repository breach after an employee device was compromised by a poisoned Nx Console VS Code extension in a supply chain attack.

Runtime Rebel Intel
3 min read · May 21, 2026
AI BOMs in Security: CISO Guide to Usability & Influence
INFO
Supply Chain

AI BOMs in Security: CISO Guide to Usability & Influence

Explore how CISOs can effectively prepare for and integrate AI Bill of Materials (AI BOMs) into their modern security programs, influencing their generation for better…

Runtime Rebel Intel
4 min read · May 20, 2026
SU
HIGH
Supply Chain

320+ @antv NPM Packages Compromised in Mini Shai-Hulud Attack

A maintainer account compromise has led to a major supply chain attack against Alibaba’s @antv NPM namespace, impacting over 320 visualization packages.

Runtime Rebel Intel
4 min read · May 20, 2026
Typosquatting Evolution: How AI Lookalike Domains Target Supply Chains
HIGH
Supply Chain

Typosquatting Evolution: How AI Lookalike Domains Target Supply Chains

Attackers are weaponizing AI-generated lookalike domains within third-party scripts, turning typosquatting into a sophisticated supply chain threat for enterprises.

Runtime Rebel Intel
3 min read · May 20, 2026
AI BOM Implementation for Enterprise Security: Bridging Visibility
INFO
Supply Chain

AI BOM Implementation for Enterprise Security: Bridging Visibility

Analyze the rise of AI Bill of Materials (AIBOMs), regulatory drivers like the EU AI Act, and the technical challenges of securing opaque AI supply chains.

Runtime Rebel Intel
3 min read · May 20, 2026
SU
HIGH
Supply Chain

GitHub Repository Breach: 3,800 Repos Accessed via VS Code Extension

GitHub confirms a security incident where a malicious VS Code extension compromised an employee account, leading to the unauthorized access of 3,800 repos.

Runtime Rebel Intel
4 min read · May 20, 2026