Skip to main content
← All Articles

Category

Supply Chain

232 articles

Advertisement

SU
HIGH
Supply Chain

Axios npm Supply Chain Attack: Malicious Payloads and Mitigation

Axios npm versions 1.14.1 and 0.30.4 compromised via a malicious dependency injecting remote access trojans. Learn how to detect and remediate this threat.

Runtime Rebel Intel
4 min read · Apr 21, 2026
Vercel Breach: Third-Party Context.ai Compromise Leads to Data Exposure
MEDIUM
Supply Chain

Vercel Breach: Third-Party Context.ai Compromise Leads to Data Exposure

Vercel reports a security incident where a compromised third-party AI tool, Context.ai, allowed attackers to access internal Google Workspace accounts.

Runtime Rebel Intel
4 min read · Apr 20, 2026
Asia's Digital Supply Chain Security: Regulatory Differences & AI Risks
INFO
Supply Chain

Asia's Digital Supply Chain Security: Regulatory Differences & AI Risks

Analyzes unique security risks in Asia's digital supply chain, highlighting challenges from regulatory disparities, interconnected ecosystems, and the rise of AI.

Runtime Rebel Intel
4 min read · Apr 15, 2026
TeamPCP Supply Chain Attack: From Credential Theft to Payroll Fraud
HIGH
Supply Chain

TeamPCP Supply Chain Attack: From Credential Theft to Payroll Fraud

TeamPCP leverages supply chain attacks to compromise trusted software, facilitating large-scale credential harvesting, logistics theft, and payroll fraud.

Runtime Rebel Intel
4 min read · Apr 15, 2026
SU
LOW
Supply Chain

Microsoft Windows Hardware Program Fast-Track Reinstatement Guide

Microsoft launches a fast-track process for developers to recover Windows Hardware Program accounts suspended during recent driver-signing security audits.

Runtime Rebel Intel
4 min read · Apr 14, 2026
SU
HIGH
Supply Chain

Trojanized CPU-Z and HWMonitor Distributed via CPUID Site Hack

Russian-speaking threat actors compromised the CPUID website to distribute STX RAT through trojanized versions of CPU-Z and HWMonitor diagnostic tools.

Runtime Rebel Intel
4 min read · Apr 13, 2026
OpenAI Revokes macOS App Certificate Following Supply Chain Attack
HIGH
Supply Chain

OpenAI Revokes macOS App Certificate Following Supply Chain Attack

OpenAI revokes its macOS app signing certificate after a GitHub Actions workflow downloaded a malicious Axios library version during a supply chain incident.

Runtime Rebel Intel
3 min read · Apr 13, 2026
CPUID Supply Chain Attack: Trojanized CPU-Z Distributes STX RAT
HIGH
Supply Chain

CPUID Supply Chain Attack: Trojanized CPU-Z Distributes STX RAT

Attackers compromised the CPUID website to distribute malicious versions of CPU-Z and HWMonitor containing the STX RAT during a 24-hour breach window.

Runtime Rebel Intel
3 min read · Apr 12, 2026
GlassWorm Campaign: Zig Dropper Infects Developer IDEs via Open VSX
HIGH
Supply Chain

GlassWorm Campaign: Zig Dropper Infects Developer IDEs via Open VSX

The GlassWorm campaign exploits the Open VSX registry with a malicious Zig-based dropper, impersonating WakaTime to compromise multiple developer IDEs.

Runtime Rebel Intel
4 min read · Apr 10, 2026
Third-Party Risk Intelligence: Beyond Legacy Cyber Risk Ratings
INFO
Supply Chain

Third-Party Risk Intelligence: Beyond Legacy Cyber Risk Ratings

Discover why modern cybersecurity strategies are shifting from static vendor risk ratings to dynamic, real-time third-party risk intelligence operations.

Runtime Rebel Intel
4 min read · Apr 10, 2026
SU
HIGH
Supply Chain

CVE-2024-21390: EngageLab SDK Vulnerability Risks Android Crypto Wallets

Microsoft reveals a vulnerability in the EngageLab SDK affecting millions of Android crypto wallet users, potentially allowing for private key theft.

Runtime Rebel Intel
3 min read · Apr 10, 2026
Smart Slider 3 Pro 3.5.1.35 Backdoor via Supply Chain Attack
HIGH
Supply Chain

Smart Slider 3 Pro 3.5.1.35 Backdoor via Supply Chain Attack

Nextend's Smart Slider 3 Pro version 3.5.1.35 was compromised via a supply chain attack. Learn how to identify and remediate the backdoor today.

Runtime Rebel Intel
3 min read · Apr 10, 2026
SU
MEDIUM
Supply Chain

Microsoft Developer Account Suspensions Block OSS Security Patches

Microsoft's suspension of high-profile open-source developer accounts disrupts security patch delivery and introduces significant supply chain risks for Windows.

Runtime Rebel Intel
4 min read · Apr 9, 2026
SU
HIGH
Supply Chain

TeamPCP Supply Chain Campaign: Cisco Source Code Stolen, UNC6780 Activity

Analysis of the TeamPCP supply chain campaign, including the theft of Cisco source code and over 1,000 compromised SaaS environments tracked by Google GTIG as UNC6780.

Runtime Rebel Intel
4 min read · Apr 9, 2026
SU
HIGH
Supply Chain

litellm 1.82.8 Supply Chain Compromise via Malicious .pth File

Security analysis of a supply chain compromise in litellm 1.82.8 on PyPI, where a malicious .pth file enables automatic code execution on Python startup.

Runtime Rebel Intel
4 min read · Apr 8, 2026
North Korean Hackers Distribute 1,700 Malicious Packages via npm and PyPI
HIGH
Supply Chain

North Korean Hackers Distribute 1,700 Malicious Packages via npm and PyPI

North Korean threat actors expand the Contagious Interview campaign, deploying 1,700 malicious packages across npm, PyPI, Go, and Rust ecosystems.

Runtime Rebel Intel
4 min read · Apr 8, 2026
SU
HIGH
Supply Chain

Snowflake Data Theft Via SaaS Integrator Breach: Mitigation

Snowflake customers face data theft due to compromised third-party SaaS integrators and stolen authentication tokens. Learn to secure integrations and detect compromise.

Runtime Rebel Intel
5 min read · Apr 7, 2026
Axios Attack: Industrialized Social Engineering on NPM Maintainers
HIGH
Supply Chain

Axios Attack: Industrialized Social Engineering on NPM Maintainers

An analysis of the Axios NPM package attack reveals advanced, scaled social engineering campaigns targeting open-source maintainers, elevating supply chain risk.

Runtime Rebel Intel
4 min read · Apr 7, 2026
AI-Assisted Supply Chain Attack Targets GitHub Misconfigurations
MEDIUM
Supply Chain

AI-Assisted Supply Chain Attack Targets GitHub Misconfigurations

Analysis of the AI-assisted PRT-scan supply chain attack targeting GitHub misconfigurations. Learn about automated threats and securing repositories.

Runtime Rebel Intel
4 min read · Apr 7, 2026
SU
HIGH
Supply Chain

North Korean Social Engineering Targets Node.js Maintainers

North Korean threat actors use social engineering and malicious npm packages to target high-profile Node.js maintainers in a sophisticated supply chain campaign.

Runtime Rebel Intel
3 min read · Apr 6, 2026
SU
HIGH
Supply Chain

Guardarian Users Targeted via 36 Malicious Strapi npm Packages

Analysis of a supply chain attack involving 36 malicious npm packages posing as Strapi plugins to target Guardarian users and harvest sensitive credentials.

Runtime Rebel Intel
4 min read · Apr 6, 2026
36 Malicious npm Packages Target Strapi, Redis, and PostgreSQL
HIGH
Supply Chain

36 Malicious npm Packages Target Strapi, Redis, and PostgreSQL

36 malicious npm packages disguised as Strapi CMS plugins target Redis and PostgreSQL environments to deploy persistent implants and reverse shells.

Runtime Rebel Intel
4 min read · Apr 5, 2026
SU
HIGH
Supply Chain

Axios npm Hijack Attempt: Detecting Social Engineering Tactics

North Korean threat actors targeted an Axios maintainer with a fake Microsoft Teams fix, highlighting critical risks to open-source supply chains.

Runtime Rebel Intel
3 min read · Apr 5, 2026
SU
HIGH
Supply Chain

European Commission AWS Breach: Trivy Supply Chain Attack Analysis

The European Commission confirms a 300GB data breach in its AWS environment linked to a Trivy supply chain attack. Learn about the impact and mitigations.

Runtime Rebel Intel
4 min read · Apr 4, 2026