Skip to main content
← All Articles

Tag

#supply-chain-attack

37 articles

Advertisement

Cordyceps: Defending Against Malicious Pull Requests in CI/CD
HIGH
Supply Chain

Cordyceps: Defending Against Malicious Pull Requests in CI/CD

The Cordyceps campaign highlights critical CI/CD vulnerabilities in GitHub Actions, targeting high-profile projects like Apache Doris and Cloudflare Workers SDK.

Runtime Rebel Intel
4 min read·Jun 24, 2026
SU
HIGH
Supply Chain

GitHub Supply Chain Disruption: Microsoft Repos Abused to Host Malware

GitHub recently disabled 73 official Microsoft repositories after they were targeted in a massive campaign pushing password-stealing malware to developers.

Runtime Rebel Intel
4 min read·Jun 9, 2026
SU
HIGH
Supply Chain

IronWorm Malware: 36 npm Packages Identified in Supply Chain Attack

Security researchers discover a campaign delivering IronWorm infostealer malware via 36 malicious npm packages using preinstall script execution hooks.

Runtime Rebel Intel
3 min read·Jun 4, 2026
TH
HIGH
Threat Intel

Glassworm Botnet Infrastructure Disrupted: Solana and DHT C2 Analysis

Researchers disrupt the Glassworm botnet, which utilized Solana blockchain and BitTorrent DHT for resilient C2 to target software developers.

Runtime Rebel Intel
3 min read·May 27, 2026
Laravel-Lang PHP Packages Compromised: Credential Stealer Alert
HIGH
Supply Chain

Laravel-Lang PHP Packages Compromised: Credential Stealer Alert

Multiple Laravel-Lang PHP packages have been compromised to deliver a cross-platform credential stealer. Learn how to detect and mitigate this supply chain threat.

Runtime Rebel Intel
4 min read·May 23, 2026
Linux Rootkits and Router Zero-Day Exploits: ThreatsDay Analysis
HIGH
Threat Intel

Linux Rootkits and Router Zero-Day Exploits: ThreatsDay Analysis

Recent intelligence highlights a surge in Linux rootkits and router zero-day vulnerabilities targeting trusted system components and AI-driven intrusions.

Runtime Rebel Intel
4 min read·May 21, 2026
SU
HIGH
Supply Chain

GitHub Repository Breach Linked to TanStack Supply Chain Attack

GitHub confirms the breach of 3,800 internal repositories via a compromised VS Code extension linked to the TanStack npm supply chain attack.

Runtime Rebel Intel
4 min read·May 21, 2026
GitHub Actions Supply Chain Attack: actions-cool/issues-helper
HIGH
Supply Chain

GitHub Actions Supply Chain Attack: actions-cool/issues-helper

Analysis of the actions-cool/issues-helper supply chain attack where tags were redirected to steal credentials. Learn how to detect and mitigate this threat.

Runtime Rebel Intel
3 min read·May 19, 2026
SU
HIGH
Supply Chain

Shai-Hulud Infostealer Surfaces in Malicious npm Package Campaign

Leaked Shai-Hulud malware is targeting Node.js developers via malicious npm packages, exfiltrating sensitive data and credentials to Telegram-based C2.

Runtime Rebel Intel
4 min read·May 18, 2026
Microsoft Exchange Zero-Day and npm Supply Chain Worm Under Active Use
CRITICAL
Threat Intel

Microsoft Exchange Zero-Day and npm Supply Chain Worm Under Active Use

Critical security briefing on the active exploitation of an Exchange Server zero-day, npm supply chain worms, and Cisco network control vulnerabilities.

Runtime Rebel Intel
3 min read·May 18, 2026
RubyGems Signups Suspended Amid Massive Malicious Package Attack
HIGH
Supply Chain

RubyGems Signups Suspended Amid Massive Malicious Package Attack

RubyGems halts new registrations after hundreds of malicious packages flood the registry, signaling a major supply chain security threat for Ruby developers.

Runtime Rebel Intel
4 min read·May 12, 2026
Mini Shai-Hulud Worm Compromises TanStack and Mistral AI Packages
CRITICAL
Supply Chain

Mini Shai-Hulud Worm Compromises TanStack and Mistral AI Packages

TeamPCP actor compromises major npm and PyPI packages including TanStack and Mistral AI via the Mini Shai-Hulud worm, deploying profiling malware.

Runtime Rebel Intel
4 min read·May 12, 2026