Skip to main content
← All Articles

Tag

#Supply Chain Attack

67 articles

Advertisement

SU
CRITICAL
Supply Chain

Red Hat npm Supply Chain Compromise: Miasma Steals Dev Credentials

Over 30 Red Hat npm packages under @redhat-cloud-services were compromised in a supply chain attack distributing Miasma malware to steal developer credentials.

Runtime Rebel Intel
5 min read·Jun 2, 2026
Miasma Supply Chain Attack: Defending Red Hat npm Environments
CRITICAL
Supply Chain

Miasma Supply Chain Attack: Defending Red Hat npm Environments

Analysis of the Miasma supply chain attack targeting Red Hat npm packages with credential-stealing worms. Technical details and mitigation guide for SOC teams.

Runtime Rebel Intel
3 min read·Jun 1, 2026
Shai-Hulud Campaign: TeamPCP Targets Open-Source Supply Chain
HIGH
Supply Chain

Shai-Hulud Campaign: TeamPCP Targets Open-Source Supply Chain

Analysis of the Shai-Hulud campaign by TeamPCP, detailing their open-source supply chain attacks, TTPs, and critical mitigation strategies.

Runtime Rebel Intel
5 min read·May 26, 2026
SU
CRITICAL
Supply Chain

TeamPCP Supply Chain Attack Targets Microsoft SDKs and GitHub

TeamPCP expands its supply chain campaign to trojanize official Microsoft Python SDKs and infiltrate GitHub, requiring immediate dependency audits.

Runtime Rebel Intel
3 min read·May 25, 2026
SU
HIGH
Supply Chain

Megalodon Supply Chain Attack Infects 5,500+ GitHub Repositories

Attackers used automated commits to inject malicious GitHub Actions workflows into 5,500+ repositories, targeting CI/CD secrets and sensitive tokens.

Runtime Rebel Intel
3 min read·May 25, 2026
Packagist Supply Chain Attack: 8 Packages Deliver Linux Malware
HIGH
Supply Chain

Packagist Supply Chain Attack: 8 Packages Deliver Linux Malware

Security researchers identified a supply chain attack on Packagist involving eight infected packages that deploy Linux malware via GitHub Releases URLs.

Runtime Rebel Intel
3 min read·May 23, 2026
DA
HIGH
Data Breach

Grafana Breach After TanStack Attack: Token Rotation Failure

Grafana suffered a data breach due to a GitHub workflow token not rotated after the TanStack npm supply-chain attack, impacting user data. Learn the details.

Runtime Rebel Intel
4 min read·May 20, 2026
SU
HIGH
Supply Chain

GitHub Repository Breach: 3,800 Repos Accessed via VS Code Extension

GitHub confirms a security incident where a malicious VS Code extension compromised an employee account, leading to the unauthorized access of 3,800 repos.

Runtime Rebel Intel
4 min read·May 20, 2026
Nx Console 18.95.0 Compromise: VS Code Extension Credential Stealer
HIGH
Supply Chain

Nx Console 18.95.0 Compromise: VS Code Extension Credential Stealer

Security researchers have identified a compromised version of the Nx Console VS Code extension (18.95.0) containing a malicious credential stealer.

Runtime Rebel Intel
3 min read·May 19, 2026
SU
HIGH
Supply Chain

TeamPCP Jenkins Plugin Compromise and Mini Shai-Hulud Worm Analysis

TeamPCP escalates its supply chain campaign with a confirmed Jenkins plugin compromise and a self-spreading worm targeting the npm and PyPI ecosystems.

Runtime Rebel Intel
3 min read·May 18, 2026
OpenAI Employee Devices Targeted in TanStack Supply Chain Attack
HIGH
Supply Chain

OpenAI Employee Devices Targeted in TanStack Supply Chain Attack

OpenAI reports compromise of two employee macOS devices via the TanStack supply chain attack. Learn how to detect and mitigate the Mini Shai-Hulud threat.

Runtime Rebel Intel
4 min read·May 15, 2026
SecurityScorecard Acquires Driftnet: Boosting Supply Chain Threat Intelligence
INFO
Threat Intel

SecurityScorecard Acquires Driftnet: Boosting Supply Chain Threat Intelligence

SecurityScorecard's acquisition of Driftnet aims to enhance third-party ecosystem visibility, strengthening defenses against supply chain attack vectors.

Runtime Rebel Intel
4 min read·May 15, 2026