Skip to main content
← All Articles

Tag

#supply-chain-attack

37 articles

Advertisement

SU
HIGH
Supply Chain

PyPI Supply Chain Threat: Deceptive Packages Target Developers

Analysis of malicious Python packages such as cryptography-util using deceptive naming to exfiltrate Discord tokens and system metadata via webhooks.

Runtime Rebel Intel
3 min read·May 11, 2026
SU
HIGH
Supply Chain

JDownloader Site Compromise: Python RAT Distribution Analysis

Attackers compromised JDownloader's site to distribute malicious installers containing a Python-based RAT. Learn how to detect and mitigate this threat.

Runtime Rebel Intel
4 min read·May 9, 2026
Microsoft Edge Plaintext Password Exposure and ICS Zero-Day Risks
CRITICAL
Threat Intel

Microsoft Edge Plaintext Password Exposure and ICS Zero-Day Risks

Analysis of Microsoft Edge plaintext password storage risks, newly disclosed ICS zero-day vulnerabilities, and Telegram-based data exfiltration TTPs.

Runtime Rebel Intel
3 min read·May 7, 2026
SAP npm Packages Compromised by “Mini Shai-Hulud” Malware
HIGH
Supply Chain

SAP npm Packages Compromised by “Mini Shai-Hulud” Malware

The Mini Shai-Hulud campaign targets SAP cloud application developers with credential-stealing npm packages. Learn how to detect and mitigate this threat.

Runtime Rebel Intel
4 min read·Apr 29, 2026
Fast16 Malware and XChat Exploitation: A Supply Chain Alert
HIGH
Threat Intel

Fast16 Malware and XChat Exploitation: A Supply Chain Alert

Analysis of Fast16 malware, XChat launch vulnerabilities, and the resurgence of remote tool abuse in enterprise software supply chains.

Runtime Rebel Intel
3 min read·Apr 27, 2026
Bitwarden CLI Supply Chain Attack: Malicious NPM Package Identified
CRITICAL
Supply Chain

Bitwarden CLI Supply Chain Attack: Malicious NPM Package Identified

Researchers have discovered a malicious payload in version 2026.4.0 of the Bitwarden CLI, targeting sensitive vault credentials in build environments.

Runtime Rebel Intel
3 min read·Apr 23, 2026
Checkmarx KICS Docker Repository and VS Code Extension Hijacked
HIGH
Supply Chain

Checkmarx KICS Docker Repository and VS Code Extension Hijacked

Unknown threat actors hijacked the checkmarx/kics Docker Hub repository, overwriting official image tags to distribute malicious code via supply chain.

Runtime Rebel Intel
4 min read·Apr 22, 2026
Vercel Breach: Third-Party Context.ai Compromise Leads to Data Exposure
HIGH
Supply Chain

Vercel Breach: Third-Party Context.ai Compromise Leads to Data Exposure

Vercel reports a security incident where a compromised third-party AI tool, Context.ai, allowed attackers to access internal Google Workspace accounts.

Runtime Rebel Intel
3 min read·Apr 20, 2026
TeamPCP Supply Chain Attack: From Credential Theft to Payroll Fraud
HIGH
Supply Chain

TeamPCP Supply Chain Attack: From Credential Theft to Payroll Fraud

TeamPCP leverages supply chain attacks to compromise trusted software, facilitating large-scale credential harvesting, logistics theft, and payroll fraud.

Runtime Rebel Intel
4 min read·Apr 15, 2026
Smart Slider 3 Pro 3.5.1.35 Backdoor via Supply Chain Attack
CRITICAL
Supply Chain

Smart Slider 3 Pro 3.5.1.35 Backdoor via Supply Chain Attack

Nextend's Smart Slider 3 Pro version 3.5.1.35 was compromised via a supply chain attack. Learn how to identify and remediate the backdoor today.

Runtime Rebel Intel
3 min read·Apr 10, 2026
SU
HIGH
Supply Chain

litellm 1.82.8 Supply Chain Compromise via Malicious .pth File

Security analysis of a supply chain compromise in litellm 1.82.8 on PyPI, where a malicious .pth file enables automatic code execution on Python startup.

Runtime Rebel Intel
3 min read·Apr 8, 2026
SU
HIGH
Supply Chain

Guardarian Users Targeted via 36 Malicious Strapi npm Packages

Analysis of a supply chain attack involving 36 malicious npm packages posing as Strapi plugins to target Guardarian users and harvest sensitive credentials.

Runtime Rebel Intel
4 min read·Apr 6, 2026