Skip to main content
← All Articles

Category

Supply Chain

232 articles

Advertisement

SU
HIGH
Supply Chain

JDownloader Site Compromise: Python RAT Distribution Analysis

Attackers compromised JDownloader's site to distribute malicious installers containing a Python-based RAT. Learn how to detect and mitigate this threat.

Runtime Rebel Intel
4 min read · May 9, 2026
SU
HIGH
Supply Chain

Fake OpenAI Hugging Face Repository Distributes Infostealer Malware

Attackers leveraged a fraudulent OpenAI repository on Hugging Face to distribute infostealers. Learn to detect and mitigate these AI supply chain threats.

Runtime Rebel Intel
3 min read · May 9, 2026
SU
INFO
Supply Chain

Boost Security Expands SDLC Defense via Strategic Acquisitions

Boost Security secures $4 million and acquires SecureIQx and Korbit.ai to streamline automated governance and security within the development lifecycle.

Runtime Rebel Intel
3 min read · May 7, 2026
Google Android Binary Transparency: Defending Against Supply Chain Attacks
INFO
Supply Chain

Google Android Binary Transparency: Defending Against Supply Chain Attacks

Google expands Binary Transparency to Android apps, providing a public ledger to verify app integrity and mitigate risks of mobile supply chain attacks.

Runtime Rebel Intel
4 min read · May 6, 2026
DAEMON Tools Supply Chain Attack: Compromised Official Installers
HIGH
Supply Chain

DAEMON Tools Supply Chain Attack: Compromised Official Installers

Official DAEMON Tools installers were compromised in a supply chain attack to distribute malware signed with legitimate certificates. Technical analysis and mitigation.

Runtime Rebel Intel
4 min read · May 6, 2026
SU
HIGH
Supply Chain

Backdoored PyTorch Lightning Package Drops Credential Stealer

A malicious PyTorch Lightning package on PyPI delivers a credential stealer, targeting browser data, environment variables, and cloud service credentials. Urgent action…

Runtime Rebel Intel
4 min read · May 4, 2026
TeamPCP Targets SAP npm Packages: Mini Shai-Hulud Supply Chain Attack
HIGH
Supply Chain

TeamPCP Targets SAP npm Packages: Mini Shai-Hulud Supply Chain Attack

TeamPCP broadens supply chain attacks, compromising npm packages in SAP's cloud development ecosystem with the 'Mini Shai-Hulud' malicious code injection.

Runtime Rebel Intel
4 min read · May 1, 2026
PyTorch Lightning 2.6.2/2.6.3 Compromise: Credential Theft Via Supply Chain
HIGH
Supply Chain

PyTorch Lightning 2.6.2/2.6.3 Compromise: Credential Theft Via Supply Chain

Threat actors injected malicious code into PyTorch Lightning versions 2.6.2 and 2.6.3 on PyPI, enabling credential theft via a supply chain attack. Urgent action…

Runtime Rebel Intel
5 min read · Apr 30, 2026
SU
MEDIUM
Supply Chain

SAP NPM Supply Chain Attack: Analyzing the Mini Shai-Hulud Campaign

Security researchers identified a malicious supply chain attack targeting SAP via NPM packages using the Bun runtime to evade traditional EDR detection.

Runtime Rebel Intel
4 min read · Apr 30, 2026
SU
HIGH
Supply Chain

Official SAP npm Packages Compromised in TeamPCP Supply Chain Attack

Attackers compromised official SAP npm packages to exfiltrate developer credentials and tokens. Learn how to detect and remediate this supply chain threat.

Runtime Rebel Intel
4 min read · Apr 30, 2026
AI-Generated npm Supply Chain Attack: DPRK Exploits Claude Opus
HIGH
Supply Chain

AI-Generated npm Supply Chain Attack: DPRK Exploits Claude Opus

North Korean actors leverage LLMs like Claude Opus to insert malicious npm packages into developer workflows, leading to RCE and data theft via @validate-sdk/v2.

Runtime Rebel Intel
4 min read · Apr 29, 2026
SAP npm Packages Compromised by “Mini Shai-Hulud” Malware
HIGH
Supply Chain

SAP npm Packages Compromised by “Mini Shai-Hulud” Malware

The Mini Shai-Hulud campaign targets SAP cloud application developers with credential-stealing npm packages. Learn how to detect and mitigate this threat.

Runtime Rebel Intel
4 min read · Apr 29, 2026
SU
HIGH
Supply Chain

Checkmarx Supply Chain Attack: GitHub Data Exfiltration Confirmed

Checkmarx confirms data exfiltration from its GitHub environment following a malicious code publication. Learn about the TTPs and mitigation strategies.

Runtime Rebel Intel
4 min read · Apr 29, 2026
GlassWorm Campaign Leverages Malicious VS Code Extensions
MEDIUM
Supply Chain

GlassWorm Campaign Leverages Malicious VS Code Extensions

Runtime Rebel details the GlassWorm campaign, which infects developers via malicious Visual Studio Code extensions on Open VSX, facilitating a supply chain attack.

Runtime Rebel Intel
5 min read · Apr 28, 2026
SU
MEDIUM
Supply Chain

GlassWorm Malware: Cloned Open VSX Extensions Target Developers

Over 70 malicious Open VSX extensions cloned from popular tools deliver GlassWorm malware, highlighting risks in developer-focused supply chain attacks.

Runtime Rebel Intel
3 min read · Apr 28, 2026
SU
HIGH
Supply Chain

TeamPCP Supply Chain: Checkmarx KICS, Bitwarden CLI, xinference PyPI Attacks

TeamPCP resumes supply chain attacks with new compromises targeting Checkmarx KICS, Bitwarden CLI, and xinference PyPI. UNC6780 credential theft campaign continues.

Runtime Rebel Intel
5 min read · Apr 27, 2026
SU
MEDIUM
Supply Chain

Malicious PyPI Package elementary-data Hijacked for Infostealer

High-profile supply chain attack on the elementary-data PyPI package compromises developer credentials and crypto wallets via account takeover. Patch now.

Runtime Rebel Intel
4 min read · Apr 27, 2026
Checkmarx GitHub Repository Data Leaked Following Supply Chain Attack
HIGH
Supply Chain

Checkmarx GitHub Repository Data Leaked Following Supply Chain Attack

Checkmarx confirms internal GitHub repository data was published on the dark web following a March 2026 supply chain incident. Learn the impact and TTPs.

Runtime Rebel Intel
4 min read · Apr 27, 2026
SU
HIGH
Supply Chain

Bitwarden NPM Supply Chain Attack: Analyzing the TeamPCP Campaign

A malicious npm package impersonating Bitwarden was discovered exfiltrating sensitive data via the Shai-Hulud worm in a recent supply chain attack.

Runtime Rebel Intel
4 min read · Apr 24, 2026
SU
HIGH
Supply Chain

Supply Chain Attack: Bitwarden CLI npm Package Compromised

Analysis of the Bitwarden CLI npm package compromise (version 2023.12.0) leading to developer credential theft and supply chain risk. Includes mitigation.

Runtime Rebel Intel
5 min read · Apr 23, 2026
SU
INFO
Supply Chain

Cloudsmith Funding Boosts Software Supply Chain Security Efforts

Cloudsmith secures $72M in Series C funding to accelerate development of its software supply chain management platform, enhancing artifact security and integrity.

Runtime Rebel Intel
4 min read · Apr 23, 2026
SU
HIGH
Supply Chain

Compromised Checkmarx KICS: Supply Chain Attack on Developer Environments

A supply chain attack compromised Checkmarx KICS Docker images and extensions, exposing developer environments to sensitive data theft. Learn mitigation.

Runtime Rebel Intel
4 min read · Apr 23, 2026
CanisterSprawl Worm: npm Package Supply Chain Hijack & Token Theft
HIGH
Supply Chain

CanisterSprawl Worm: npm Package Supply Chain Hijack & Token Theft

New CanisterSprawl worm compromises npm packages, propagates by stealing developer tokens via an ICP canister. Threatens software supply chain integrity.

Runtime Rebel Intel
4 min read · Apr 22, 2026
Checkmarx KICS Docker Repository and VS Code Extension Hijacked
HIGH
Supply Chain

Checkmarx KICS Docker Repository and VS Code Extension Hijacked

Unknown threat actors hijacked the checkmarx/kics Docker Hub repository, overwriting official image tags to distribute malicious code via supply chain.

Runtime Rebel Intel
4 min read · Apr 22, 2026