Skip to main content
← All Articles

Category

Supply Chain

232 articles

Advertisement

SU
HIGH
Supply Chain

TeamPCP Supply Chain: CERT-EU Confirms Cloud Breach, 1000+ SaaS Environments Affected

CERT-EU confirms European Commission cloud breach via TeamPCP supply chain campaign. Mandiant identifies over 1,000 compromised SaaS environments. Learn about…

Runtime Rebel Intel
5 min read · Apr 3, 2026
Third-Party Risk: The Growing Supply Chain Security Gap
HIGH
Supply Chain

Third-Party Risk: The Growing Supply Chain Security Gap

Organizations face increasing breach risks through trusted vendors, SaaS tools, and subcontractors. Learn to identify and mitigate third-party supply chain…

Runtime Rebel Intel
5 min read · Apr 3, 2026
UNC1069 Social Engineering Leads to Axios npm Supply Chain Compromise
HIGH
Supply Chain

UNC1069 Social Engineering Leads to Axios npm Supply Chain Compromise

Runtime Rebel details how North Korean threat actor UNC1069 leveraged targeted social engineering against an Axios npm package maintainer, leading to a critical supply…

Runtime Rebel Intel
4 min read · Apr 3, 2026
SU
MEDIUM
Supply Chain

FCC Regulates Foreign Consumer Routers Over Supply Chain Risk

The US Executive Branch and FCC have restricted foreign-made consumer routers to mitigate critical infrastructure risks and supply chain vulnerabilities.

Runtime Rebel Intel
3 min read · Apr 3, 2026
SU
HIGH
Supply Chain

Mercor Hit by LiteLLM Supply Chain Attack – Lapsus$ Claims 4TB Data Theft

AI recruiting firm Mercor is investigating a LiteLLM supply chain attack, with Lapsus$ claiming to have stolen 4TB of sensitive data.

Runtime Rebel Intel
4 min read · Apr 2, 2026
Open Source Security: Key Findings from 2025 Trust Report
INFO
Supply Chain

Open Source Security: Key Findings from 2025 Trust Report

Analysis of the 2025 State of Trusted Open Source Report, detailing prevalent vulnerabilities and consumption patterns in container images and language libraries.

Runtime Rebel Intel
4 min read · Apr 2, 2026
SU
HIGH
Supply Chain

Stardust Chollima Compromises Axios npm Package

Technical analysis of the Stardust Chollima supply chain attack targeting the Axios npm package to exfiltrate developer credentials and data.

Runtime Rebel Intel
4 min read · Apr 2, 2026
SU
HIGH
Supply Chain

TeamPCP Supply Chain Campaign: First Victim, Cloud Enumeration, Ransomware

Detailed analysis of TeamPCP supply chain campaign, covering the first confirmed victim, post-compromise cloud enumeration tactics, and dual ransomware operations.

Runtime Rebel Intel
4 min read · Apr 1, 2026
SU
HIGH
Supply Chain

Axios NPM Supply Chain Attack Bypasses GitHub Actions CI/CD

A sophisticated supply chain attack targeted the Axios NPM package, leveraging a compromised token to bypass GitHub Actions CI/CD and deploy malicious versions.

Runtime Rebel Intel
4 min read · Apr 1, 2026
Claude Code Source Leaked via npm Packaging Error
MEDIUM
Supply Chain

Claude Code Source Leaked via npm Packaging Error

Anthropic confirms internal Claude Code source code was leaked due to an npm packaging error. Analysis of supply chain risks and mitigation strategies.

Runtime Rebel Intel
4 min read · Apr 1, 2026
Axios npm Supply Chain Attack Attributed to North Korea's UNC1069
HIGH
Supply Chain

Axios npm Supply Chain Attack Attributed to North Korea's UNC1069

Google Threat Intelligence attributes a major Axios npm supply chain attack to North Korean group UNC1069, emphasizing risks to developer environments.

Runtime Rebel Intel
4 min read · Apr 1, 2026
SU
HIGH
Supply Chain

UNC1069 Leverages Axios NPM Supply Chain to Deploy WAVESHAPER.V2

North Korea-nexus UNC1069 compromised widely used Axios NPM package (v1.14.1, 0.30.4) by injecting plain-crypto-js to deploy WAVESHAPER.V2 backdoor across multiple OS.

Runtime Rebel Intel
8 min read · Apr 1, 2026
Axios NPM Compromise: Supply Chain Threat Analysis
HIGH
Supply Chain

Axios NPM Compromise: Supply Chain Threat Analysis

Analysis of the Axios NPM package compromise, a potential supply chain attack impacting JavaScript HTTP client library users, possibly by North Korean threat actors.

Runtime Rebel Intel
5 min read · Apr 1, 2026
SU
MEDIUM
Supply Chain

Anthropic Claude Code Source Code Leaked via NPM Registry

Anthropic accidentally exposed proprietary source code for its Claude Code CLI tool on the public npm registry. Analyze the technical impact and risks.

Runtime Rebel Intel
3 min read · Apr 1, 2026
SU
HIGH
Supply Chain

Cisco Source Code Stolen: Trivy Supply Chain Attack Leads to Breach

Threat actors breached Cisco's dev environment using credentials from a Trivy supply chain attack, stealing proprietary and customer source code. Learn the impact and…

Runtime Rebel Intel
4 min read · Mar 31, 2026
SU
HIGH
Supply Chain

Axios npm Package Hijacked: Cross-Platform Malware Distribution

Analysis of the Axios npm package hijack distributing remote access trojans to Linux, Windows, and macOS systems. Learn to protect your software supply chain.

Runtime Rebel Intel
5 min read · Mar 31, 2026
Axios Supply Chain Attack: RAT Found in Versions 1.14.1 and 0.30.4
HIGH
Supply Chain

Axios Supply Chain Attack: RAT Found in Versions 1.14.1 and 0.30.4

Malicious Axios versions 1.14.1 and 0.30.4 inject a cross-platform RAT via a fake dependency. Identify and remediate this npm supply chain threat now.

Runtime Rebel Intel
4 min read · Mar 31, 2026
SU
HIGH
Supply Chain

TeamPCP Supply Chain Campaign: Databricks and AstraZeneca Impact

TeamPCP's supply chain campaign weaponizes security scanners for dual ransomware operations, impacting Databricks and AstraZeneca in a major breach.

Runtime Rebel Intel
4 min read · Mar 30, 2026
SU
HIGH
Supply Chain

TeamPCP Supply Chain Campaign: Weaponized Scanners and PyPI Compromise

Analysis of the TeamPCP campaign transition to monetization following the Telnyx PyPI compromise and Vect ransomware partnership affecting security tools.

Runtime Rebel Intel
4 min read · Mar 28, 2026
SU
HIGH
Supply Chain

Backdoored Telnyx PyPI Package Uses Steganography to Deliver Malware

Security researchers discovered malicious versions of the Telnyx PyPI package delivering infostealers via steganography hidden in WAV audio files.

Runtime Rebel Intel
3 min read · Mar 28, 2026
Telnyx PyPI Package Compromised by TeamPCP via Steganography
HIGH
Supply Chain

Telnyx PyPI Package Compromised by TeamPCP via Steganography

TeamPCP threat actors distributed malicious Telnyx Python package versions 4.87.1 and 4.87.2 on PyPI to harvest credentials using hidden WAV files.

Runtime Rebel Intel
4 min read · Mar 27, 2026
SU
HIGH
Supply Chain

TeamPCP Supply Chain Attack: Telnyx PyPI Compromise and Vect Ransomware

TeamPCP campaign escalates with Telnyx PyPI compromise and Vect Ransomware mass affiliate program. Critical update for software developers and SOC teams.

Runtime Rebel Intel
4 min read · Mar 27, 2026
Open VSX Registry Security Bypass: Malicious VS Code Extensions Risk
HIGH
Supply Chain

Open VSX Registry Security Bypass: Malicious VS Code Extensions Risk

A logic error in the Open VSX pre-publish scanning pipeline allowed malicious VS Code extensions to bypass security checks. Read our technical analysis.

Runtime Rebel Intel
3 min read · Mar 27, 2026
FCC Router Ban: Analyzing Supply Chain Risks & Consumer Security
INFO
Supply Chain

FCC Router Ban: Analyzing Supply Chain Risks & Consumer Security

The FCC's ban on foreign-made consumer routers aims to enhance national security but raises concerns about supply chain transparency, grey markets, and actual consumer…

Runtime Rebel Intel
5 min read · Mar 27, 2026