Skip to main content
← All Articles

Tag

#Supply Chain Attack

226 articles

Advertisement

NastyC2 npm Packages, AI Abuse & macOS Threats Identified
HIGH
Threat Intel

NastyC2 npm Packages, AI Abuse & macOS Threats Identified

Analysis of NastyC2 npm supply chain attacks, Claude chat abuse for malware, memory-resident macOS threats, and device-code phishing.

Runtime Rebel Intel
4 min read · Jun 18, 2026
HIGH
Supply Chain

OptinMonster 2.6.5 Update: Managing CDN Supply Chain Attack Risks

Learn how the OptinMonster CDN supply chain attack compromised over 1 million WordPress sites and how to mitigate the risk of malicious script injection.

Runtime Rebel Intel
4 min read · Jun 15, 2026
INFO
Supply Chain

npm 12 Security: Default Script Execution Changes to Mitigate Supply Chain Attacks

npm 12 introduces a critical change: 'npm install' will no longer run dependency scripts by default, significantly reducing software supply chain risks.

Runtime Rebel Intel
4 min read · Jun 13, 2026
400+ Arch Linux AUR Packages Hijacked: eBPF Rootkit and Infostealer
HIGH
Supply Chain

400+ Arch Linux AUR Packages Hijacked: eBPF Rootkit and Infostealer

Attackers compromised over 400 Arch User Repository (AUR) packages to deploy Rust-based infostealers and eBPF rootkits, targeting developer credentials.

Runtime Rebel Intel
4 min read · Jun 12, 2026
MEDIUM
Supply Chain

AUR Compromise: 400+ Packages Distributing Rootkits and Infostealers

Over 400 Arch User Repository (AUR) packages compromised to deploy Linux rootkits and harvest credentials, tokens, and sensitive developer data.

Runtime Rebel Intel
4 min read · Jun 12, 2026
Agentjacking: Tricking AI Coding Agents into Malicious Code Execution
HIGH
Threat Intel

Agentjacking: Tricking AI Coding Agents into Malicious Code Execution

Agentjacking is a new attack where crafted Sentry error reports trick AI coding agents into executing arbitrary code on developer systems, risking intellectual property…

Runtime Rebel Intel
5 min read · Jun 12, 2026

Advertisement

OceanLotus Targets Vietnam with SPECTRALVIPER Backdoor in FireAnt Attack
HIGH
Threat Intel

OceanLotus Targets Vietnam with SPECTRALVIPER Backdoor in FireAnt Attack

OceanLotus APT targets Vietnamese infrastructure and stock investors with SPECTRALVIPER backdoor in multi-year cyber espionage and supply chain campaigns.

Runtime Rebel Intel
4 min read · Jun 11, 2026
HIGH
Malware

Miasma Worm Source Code Briefly Leaked on GitHub

Analysis of the Miasma worm source code leak on GitHub, a credential-stealing framework targeting open-source ecosystems via supply-chain attacks.

Runtime Rebel Intel
4 min read · Jun 10, 2026
HIGH
Supply Chain

GitHub Supply Chain Disruption: Microsoft Repos Abused to Host Malware

GitHub recently disabled 73 official Microsoft repositories after they were targeted in a massive campaign pushing password-stealing malware to developers.

Runtime Rebel Intel
4 min read · Jun 9, 2026
Miasma Compromises 73 Microsoft GitHub Repos: Incident Analysis
HIGH
Supply Chain

Miasma Compromises 73 Microsoft GitHub Repos: Incident Analysis

Microsoft restores some GitHub repositories after 73 projects were hit by Miasma's supply chain attack to inject information stealers. Learn detection steps.

Runtime Rebel Intel
4 min read · Jun 9, 2026
HIGH
Supply Chain

Shai-Hulud Attack: Trojanized PyPI Packages Steal Developer Secrets

New Shai-Hulud supply chain attack compromises 19 science-focused PyPI packages, distributing malware to steal developer credentials and secrets.

Runtime Rebel Intel
4 min read · Jun 8, 2026
HIGH
Threat Intel

TeamPCP Campaign Update: Mini Shai-Hulud Framework Gains Adoption

Analysis of the TeamPCP supply chain campaign, the open-sourcing of the Mini Shai-Hulud framework, and its adoption by diverse threat actor groups in 2026.

Runtime Rebel Intel
4 min read · Jun 8, 2026
MEDIUM
Supply Chain

Toshiba and Muji Impacted by Polyfill Supply Chain Attack

Toshiba and Muji have warned of malicious login prompts appearing on their sites. This follows the takeover of the Polyfill.io domain used for script injection.

Runtime Rebel Intel
4 min read · Jun 6, 2026
npm Supply Chain Attack: IronWorm and Miasma Malware Analysis
HIGH
Supply Chain

npm Supply Chain Attack: IronWorm and Miasma Malware Analysis

Threat actors target npm developers with the IronWorm info stealer and Miasma worm, utilizing eBPF rootkits to exfiltrate secrets and ensure persistence.

Runtime Rebel Intel
3 min read · Jun 5, 2026
IronWorm: Rust-Written Malware Hits npm Supply Chain Developers
HIGH
Supply Chain

IronWorm: Rust-Written Malware Hits npm Supply Chain Developers

Analysis of the Rust-written IronWorm malware targeting npm supply chain developers.

Runtime Rebel Intel
5 min read · Jun 5, 2026
HIGH
Supply Chain

Hola Browser for Windows Compromised: Cryptominer Delivery via Supply Chain

Critical alert: Hola Browser for Windows compromised in a supply chain attack, delivering an undeclared cryptominer. Learn to detect and mitigate the threat.

Runtime Rebel Intel
4 min read · Jun 5, 2026
HIGH
Supply Chain

IronWorm Malware: 36 npm Packages Identified in Supply Chain Attack

Security researchers discover a campaign delivering IronWorm infostealer malware via 36 malicious npm packages using preinstall script execution hooks.

Runtime Rebel Intel
3 min read · Jun 4, 2026
HIGH
Supply Chain

Red Hat npm Supply Chain Compromise: Miasma Steals Dev Credentials

Over 30 Red Hat npm packages under @redhat-cloud-services were compromised in a supply chain attack distributing Miasma malware to steal developer credentials.

Runtime Rebel Intel
5 min read · Jun 2, 2026
Miasma Supply Chain Attack: Defending Red Hat npm Environments
HIGH
Supply Chain

Miasma Supply Chain Attack: Defending Red Hat npm Environments

Analysis of the Miasma supply chain attack targeting Red Hat npm packages with credential-stealing worms. Technical details and mitigation guide for SOC teams.

Runtime Rebel Intel
3 min read · Jun 1, 2026
HIGH
Threat Intel

Glassworm Botnet Infrastructure Disrupted: Solana and DHT C2 Analysis

Researchers disrupt the Glassworm botnet, which utilized Solana blockchain and BitTorrent DHT for resilient C2 to target software developers.

Runtime Rebel Intel
4 min read · May 27, 2026
Malicious npm Package Targets Claude AI User Data — Technical Analysis
HIGH
Supply Chain

Malicious npm Package Targets Claude AI User Data — Technical Analysis

Researchers discover mouse5212-super-formatter, a malicious npm package designed to exfiltrate sensitive files from Claude AI user directories.

Runtime Rebel Intel
3 min read · May 27, 2026
GlassWorm Malware Takedown: Disruption of Developer Supply Chain C2
HIGH
Supply Chain

GlassWorm Malware Takedown: Disruption of Developer Supply Chain C2

CrowdStrike, Google, and Shadowserver disrupt the GlassWorm malware C2 infrastructure, halting a persistent developer-focused supply chain attack campaign.

Runtime Rebel Intel
4 min read · May 27, 2026
Shai-Hulud Campaign: TeamPCP Targets Open-Source Supply Chain
HIGH
Supply Chain

Shai-Hulud Campaign: TeamPCP Targets Open-Source Supply Chain

Analysis of the Shai-Hulud campaign by TeamPCP, detailing their open-source supply chain attacks, TTPs, and critical mitigation strategies.

Runtime Rebel Intel
5 min read · May 26, 2026
Megalodon Malware: GitHub Repo Compromise & Secret Theft
HIGH
Supply Chain

Megalodon Malware: GitHub Repo Compromise & Secret Theft

Analysis of the Megalodon malware campaign, which compromised over 5,500 GitHub repositories in six hours to steal developer credentials and sensitive secrets.

Runtime Rebel Intel
4 min read · May 26, 2026