<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Malicious Packages</title><description>Cybersecurity articles tagged #Malicious Packages on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>GitHub Dependabot 3-Day Cooldown: Mitigating Supply Chain Attacks</title><link>https://runtimerebel.com/blog/github-dependabot-3-day-cooldown-mitigating-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-dependabot-3-day-cooldown-mitigating-supply-chain-attacks</guid><description>GitHub introduces a 3-day cooldown for Dependabot to prevent the rapid adoption of malicious packages, enhancing supply chain security for developers.</description><pubDate>Mon, 27 Jul 2026 11:25:20 GMT</pubDate><category>GitHub</category><category>Dependabot</category><category>Supply Chain Security</category><category>Malicious Packages</category><category>Open Source</category></item><item><title>N. Korea-Linked npm Packages Mimic Rollup Polyfills for Data Theft</title><link>https://runtimerebel.com/blog/n-korea-linked-npm-packages-mimic-rollup-polyfills-for-data-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/n-korea-linked-npm-packages-mimic-rollup-polyfills-for-data-theft</guid><description>North Korea-linked actors use malicious npm packages (&apos;rollup-packages-polyfill-core&apos;, &apos;rollup-runtime-polyfill-core&apos;) to steal developer secrets, mimicking Rollup…</description><pubDate>Fri, 03 Jul 2026 17:27:44 GMT</pubDate><category>NPM</category><category>Rollup</category><category>Supply Chain Attack</category><category>North Korea Linked</category><category>Developer Secrets</category><category>Malicious Packages</category></item><item><title>GlassWorm Malware Takedown: Disruption of Developer Supply Chain C2</title><link>https://runtimerebel.com/blog/glassworm-malware-takedown-disruption-of-developer-supply-chain-c2</link><guid isPermaLink="true">https://runtimerebel.com/blog/glassworm-malware-takedown-disruption-of-developer-supply-chain-c2</guid><description>CrowdStrike, Google, and Shadowserver disrupt the GlassWorm malware C2 infrastructure, halting a persistent developer-focused supply chain attack campaign.</description><pubDate>Wed, 27 May 2026 13:20:01 GMT</pubDate><category>GlassWorm</category><category>CrowdStrike</category><category>C2 Disruption</category><category>Supply Chain Attack</category><category>Malicious Packages</category></item><item><title>Shai-Hulud Campaign: TeamPCP Targets Open-Source Supply Chain</title><link>https://runtimerebel.com/blog/shai-hulud-campaign-teampcp-targets-open-source-supply-chain</link><guid isPermaLink="true">https://runtimerebel.com/blog/shai-hulud-campaign-teampcp-targets-open-source-supply-chain</guid><description>Analysis of the Shai-Hulud campaign by TeamPCP, detailing their open-source supply chain attacks, TTPs, and critical mitigation strategies.</description><pubDate>Tue, 26 May 2026 20:47:57 GMT</pubDate><category>TeamPCP</category><category>Shai Hulud</category><category>Supply Chain Attack</category><category>Open Source Security</category><category>NPM</category><category>PyPI</category><category>Malicious Packages</category></item><item><title>Shai-Hulud Infostealer Surfaces in Malicious npm Package Campaign</title><link>https://runtimerebel.com/blog/shai-hulud-infostealer-surfaces-in-malicious-npm-package-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/shai-hulud-infostealer-surfaces-in-malicious-npm-package-campaign</guid><description>Leaked Shai-Hulud malware is targeting Node.js developers via malicious npm packages, exfiltrating sensitive data and credentials to Telegram-based C2.</description><pubDate>Mon, 18 May 2026 20:37:20 GMT</pubDate><category>NPM</category><category>Shai Hulud</category><category>Infostealer</category><category>Supply Chain Attack</category><category>Malicious Packages</category></item><item><title>RubyGems Suspends Registrations Due to Malicious Package Influx</title><link>https://runtimerebel.com/blog/rubygems-suspends-registrations-due-to-malicious-package-influx</link><guid isPermaLink="true">https://runtimerebel.com/blog/rubygems-suspends-registrations-due-to-malicious-package-influx</guid><description>RubyGems maintainers suspended new user registrations after detecting an automated attack involving over 500 malicious packages targeting platform resources.</description><pubDate>Wed, 13 May 2026 09:09:56 GMT</pubDate><category>RubyGems</category><category>Open Source Security</category><category>Package Manager</category><category>Supply Chain Security</category><category>Malicious Packages</category></item><item><title>RubyGems Signups Suspended Amid Massive Malicious Package Attack</title><link>https://runtimerebel.com/blog/rubygems-signups-suspended-amid-massive-malicious-package-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/rubygems-signups-suspended-amid-massive-malicious-package-attack</guid><description>RubyGems halts new registrations after hundreds of malicious packages flood the registry, signaling a major supply chain security threat for Ruby developers.</description><pubDate>Tue, 12 May 2026 20:37:55 GMT</pubDate><category>RubyGems</category><category>Supply Chain Attack</category><category>Ruby Security</category><category>Malicious Packages</category><category>Registry Security</category></item><item><title>Official SAP npm Packages Compromised in TeamPCP Supply Chain Attack</title><link>https://runtimerebel.com/blog/official-sap-npm-packages-compromised-in-teampcp-supply-chain-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/official-sap-npm-packages-compromised-in-teampcp-supply-chain-attack</guid><description>Attackers compromised official SAP npm packages to exfiltrate developer credentials and tokens. Learn how to detect and remediate this supply chain threat.</description><pubDate>Thu, 30 Apr 2026 00:50:55 GMT</pubDate><category>SAP</category><category>NPM</category><category>TeamPCP</category><category>Credential Theft</category><category>Malicious Packages</category></item><item><title>Checkmarx Supply Chain Attack: GitHub Data Exfiltration Confirmed</title><link>https://runtimerebel.com/blog/checkmarx-supply-chain-attack-github-data-exfiltration-confirmed</link><guid isPermaLink="true">https://runtimerebel.com/blog/checkmarx-supply-chain-attack-github-data-exfiltration-confirmed</guid><description>Checkmarx confirms data exfiltration from its GitHub environment following a malicious code publication. Learn about the TTPs and mitigation strategies.</description><pubDate>Wed, 29 Apr 2026 12:42:21 GMT</pubDate><category>Checkmarx</category><category>GitHub</category><category>Supply Chain Attack</category><category>Data Breach</category><category>Malicious Packages</category></item><item><title>AI-Driven Package Hallucination: A New Frontier in Supply Chain Exploitation</title><link>https://runtimerebel.com/blog/ai-driven-package-hallucination-a-new-frontier-in-supply-chain-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-driven-package-hallucination-a-new-frontier-in-supply-chain-exploitation</guid><description>Analysis of a novel attack vector where autonomous AI agents facilitate malicious package injection through dependency confusion and LLM hallucinations.</description><pubDate>Mon, 23 Feb 2026 16:26:52 GMT</pubDate><category>AI Security</category><category>Supply Chain Attack</category><category>Malicious Packages</category><category>Dependency Confusion</category><category>LLM Hallucination</category></item></channel></rss>