Skip to main content
← All Articles

Tag

#Supply Chain Attack

226 articles

Advertisement

Tag Poisoning Compromises Xygeni GitHub Action, C2 Implant Active
HIGH
Supply Chain

Tag Poisoning Compromises Xygeni GitHub Action, C2 Implant Active

Attackers compromised the `xygeni/xygeni-action` GitHub Action using tag poisoning, deploying a C2 implant for up to a week. Users must verify integrity and review logs.

Runtime Rebel Intel
4 min read · Mar 12, 2026
UNC6426 Exploits nx npm Supply-Chain Attack for AWS Admin Access
HIGH
Supply Chain

UNC6426 Exploits nx npm Supply-Chain Attack for AWS Admin Access

UNC6426 leveraged stolen GitHub tokens from the nx npm compromise to achieve full AWS administrative control and data exfiltration within 72 hours.

Runtime Rebel Intel
3 min read · Mar 11, 2026
HIGH
Data Breach

Ericsson US Data Breach via Service Provider: Employee & Customer Data Compromised

Ericsson US discloses a significant data breach impacting employee and customer information, stemming from a security incident at a third-party service provider.

Runtime Rebel Intel
5 min read · Mar 9, 2026
npm Malware @openclaw-ai/openclawai: macOS Credential Theft Alert
HIGH
Supply Chain

npm Malware @openclaw-ai/openclawai: macOS Credential Theft Alert

Security alert for @openclaw-ai/openclawai, a malicious npm package targeting macOS users to deploy remote access trojans and steal sensitive credentials.

Runtime Rebel Intel
4 min read · Mar 9, 2026
Chrome Extensions QuickLens and BuildMelon Hijacked via Ownership Transfer
HIGH
Supply Chain

Chrome Extensions QuickLens and BuildMelon Hijacked via Ownership Transfer

Attackers are exploiting Chrome extension ownership transfers to weaponize QuickLens and BuildMelon tools for code injection and data harvesting.

Runtime Rebel Intel
4 min read · Mar 9, 2026
Malicious Laravel Packagist Packages Deploy Cross-Platform RAT
HIGH
Supply Chain

Malicious Laravel Packagist Packages Deploy Cross-Platform RAT

Security researchers discover malicious Laravel packages on Packagist delivering cross-platform RATs to Windows, macOS, and Linux systems. Audit your PHP dependencies.

Runtime Rebel Intel
3 min read · Mar 4, 2026

Advertisement

North Korean Malicious npm Packages: Detecting Contagious Interview
HIGH
Supply Chain

North Korean Malicious npm Packages: Detecting Contagious Interview

North Korean actors published 26 malicious npm packages using Pastebin as a C2 dead drop resolver in a new Contagious Interview campaign iteration.

Runtime Rebel Intel
4 min read · Mar 2, 2026
HIGH
Supply Chain

Fake Next.js Job Interview Tests Backdoor Developers

Microsoft Defender discovered a campaign where malicious Next.js job interview tests backdoor developers' devices, posing a supply chain risk.

Runtime Rebel Intel
5 min read · Feb 26, 2026
HIGH
Supply Chain

AI-Driven Package Hallucination: A New Frontier in Supply Chain Exploitation

Analysis of a novel attack vector where autonomous AI agents facilitate malicious package injection through dependency confusion and LLM hallucinations.

Runtime Rebel Intel
3 min read · Feb 23, 2026
SANDWORM_MODE: Malicious npm Cluster Automates Secret Harvesting and Crypto Theft
HIGH
Supply Chain

SANDWORM_MODE: Malicious npm Cluster Automates Secret Harvesting and Crypto Theft

Security researchers have identified a coordinated campaign involving 19 malicious npm packages designed to exfiltrate CI/CD secrets, API tokens, and private…

Runtime Rebel Intel
2 min read · Feb 23, 2026