Skip to main content
← All Articles

Tag

#Supply Chain Attack

226 articles

Advertisement

Checkmarx Jenkins AST Plugin Compromised in TeamPCP Attack
HIGH
Supply Chain

Checkmarx Jenkins AST Plugin Compromised in TeamPCP Attack

TeamPCP compromised the Checkmarx Jenkins AST plugin on the Jenkins Marketplace. Defenders must revert to version 2.0.13 to secure CI/CD pipelines.

Runtime Rebel Intel
3 min read · May 11, 2026
INFO
Supply Chain

Defending CI/CD Pipelines with Build Application Firewalls

Examine how Build Application Firewalls (BAF) provide runtime protection for software pipelines to mitigate sophisticated supply chain attacks and data theft.

Runtime Rebel Intel
4 min read · May 11, 2026
Fake OpenAI Privacy Filter Repository Distributes Rust Info-Stealer
HIGH
Supply Chain

Fake OpenAI Privacy Filter Repository Distributes Rust Info-Stealer

A malicious Hugging Face repository impersonating OpenAI's privacy tool reached 244k downloads, delivering a Rust-based information stealer to Windows users.

Runtime Rebel Intel
3 min read · May 11, 2026
HIGH
Supply Chain

PyPI Supply Chain Threat: Deceptive Packages Target Developers

Analysis of malicious Python packages such as cryptography-util using deceptive naming to exfiltrate Discord tokens and system metadata via webhooks.

Runtime Rebel Intel
3 min read · May 11, 2026
HIGH
Supply Chain

JDownloader Site Compromise: Python RAT Distribution Analysis

Attackers compromised JDownloader's site to distribute malicious installers containing a Python-based RAT. Learn how to detect and mitigate this threat.

Runtime Rebel Intel
4 min read · May 9, 2026
HIGH
Supply Chain

Fake OpenAI Hugging Face Repository Distributes Infostealer Malware

Attackers leveraged a fraudulent OpenAI repository on Hugging Face to distribute infostealers. Learn to detect and mitigate these AI supply chain threats.

Runtime Rebel Intel
3 min read · May 9, 2026

Advertisement

Microsoft Edge Plaintext Password Exposure and ICS Zero-Day Risks
CRITICAL
Threat Intel

Microsoft Edge Plaintext Password Exposure and ICS Zero-Day Risks

Analysis of Microsoft Edge plaintext password storage risks, newly disclosed ICS zero-day vulnerabilities, and Telegram-based data exfiltration TTPs.

Runtime Rebel Intel
3 min read · May 7, 2026
DAEMON Tools Supply Chain Attack: Compromised Official Installers
HIGH
Supply Chain

DAEMON Tools Supply Chain Attack: Compromised Official Installers

Official DAEMON Tools installers were compromised in a supply chain attack to distribute malware signed with legitimate certificates. Technical analysis and mitigation.

Runtime Rebel Intel
4 min read · May 6, 2026
HIGH
Data Breach

Trellix Source Code Breach: Understanding Potential Supply Chain Risks

A deep dive into the Trellix source code repository breach, analyzing potential supply chain implications, intellectual property risks, and recommended mitigations for…

Runtime Rebel Intel
5 min read · May 4, 2026
HIGH
Supply Chain

Backdoored PyTorch Lightning Package Drops Credential Stealer

A malicious PyTorch Lightning package on PyPI delivers a credential stealer, targeting browser data, environment variables, and cloud service credentials.

Runtime Rebel Intel
4 min read · May 4, 2026
TeamPCP Targets SAP npm Packages: Mini Shai-Hulud Supply Chain Attack
HIGH
Supply Chain

TeamPCP Targets SAP npm Packages: Mini Shai-Hulud Supply Chain Attack

TeamPCP broadens supply chain attacks, compromising npm packages in SAP's cloud development ecosystem with the 'Mini Shai-Hulud' malicious code injection.

Runtime Rebel Intel
4 min read · May 1, 2026
PyTorch Lightning 2.6.2/2.6.3 Compromise: Credential Theft Via Supply Chain
HIGH
Supply Chain

PyTorch Lightning 2.6.2/2.6.3 Compromise: Credential Theft Via Supply Chain

Threat actors injected malicious code into PyTorch Lightning versions 2.6.2 and 2.6.3 on PyPI, enabling credential theft via a supply chain attack.

Runtime Rebel Intel
5 min read · Apr 30, 2026
SAP npm Packages Compromised by “Mini Shai-Hulud” Malware
HIGH
Supply Chain

SAP npm Packages Compromised by “Mini Shai-Hulud” Malware

The Mini Shai-Hulud campaign targets SAP cloud application developers with credential-stealing npm packages. Learn how to detect and mitigate this threat.

Runtime Rebel Intel
4 min read · Apr 29, 2026
HIGH
Supply Chain

Checkmarx Supply Chain Attack: GitHub Data Exfiltration Confirmed

Checkmarx confirms data exfiltration from its GitHub environment following a malicious code publication. Learn about the TTPs and mitigation strategies.

Runtime Rebel Intel
4 min read · Apr 29, 2026
Lazarus Group's $2B+ Crypto Theft: Defending Against Supply Chain Attacks
HIGH
Threat Intel

Lazarus Group's $2B+ Crypto Theft: Defending Against Supply Chain Attacks

An analysis of Lazarus Group's persistent and financially motivated cyber operations, highlighting over $2B in crypto theft and critical supply chain attack risks.

Runtime Rebel Intel
5 min read · Apr 28, 2026
GlassWorm Campaign Leverages Malicious VS Code Extensions
MEDIUM
Supply Chain

GlassWorm Campaign Leverages Malicious VS Code Extensions

Runtime Rebel details the GlassWorm campaign, which infects developers via malicious Visual Studio Code extensions on Open VSX, facilitating a supply chain attack.

Runtime Rebel Intel
5 min read · Apr 28, 2026
MEDIUM
Supply Chain

GlassWorm Malware: Cloned Open VSX Extensions Target Developers

Over 70 malicious Open VSX extensions cloned from popular tools deliver GlassWorm malware, highlighting risks in developer-focused supply chain attacks.

Runtime Rebel Intel
3 min read · Apr 28, 2026
HIGH
Malware

GlassWorm Malware Resurfaces via 73 OpenVSX Sleeper Extensions

A new GlassWorm campaign exploits the OpenVSX ecosystem with 73 'sleeper' extensions, posing a significant supply chain threat to developers.

Runtime Rebel Intel
4 min read · Apr 28, 2026
HIGH
Supply Chain

TeamPCP Supply Chain: Checkmarx KICS, Bitwarden CLI, xinference PyPI Attacks

TeamPCP resumes supply chain attacks with new compromises targeting Checkmarx KICS, Bitwarden CLI, and xinference PyPI. UNC6780 credential theft campaign continues.

Runtime Rebel Intel
5 min read · Apr 27, 2026
Fast16 Malware and XChat Exploitation: A Supply Chain Alert
HIGH
Threat Intel

Fast16 Malware and XChat Exploitation: A Supply Chain Alert

Analysis of Fast16 malware, XChat launch vulnerabilities, and the resurgence of remote tool abuse in enterprise software supply chains.

Runtime Rebel Intel
3 min read · Apr 27, 2026
Checkmarx GitHub Repository Data Leaked Following Supply Chain Attack
HIGH
Supply Chain

Checkmarx GitHub Repository Data Leaked Following Supply Chain Attack

Checkmarx confirms internal GitHub repository data was published on the dark web following a March 2026 supply chain incident. Learn the impact and TTPs.

Runtime Rebel Intel
4 min read · Apr 27, 2026
HIGH
Supply Chain

Supply Chain Attack: Bitwarden CLI npm Package Compromised

Analysis of the Bitwarden CLI npm package compromise (version 2023.12.0) leading to developer credential theft and supply chain risk. Includes mitigation.

Runtime Rebel Intel
5 min read · Apr 23, 2026
HIGH
Supply Chain

Compromised Checkmarx KICS: Supply Chain Attack on Developer Environments

A supply chain attack compromised Checkmarx KICS Docker images and extensions, exposing developer environments to sensitive data theft. Learn mitigation.

Runtime Rebel Intel
4 min read · Apr 23, 2026
Checkmarx KICS Docker Repository and VS Code Extension Hijacked
HIGH
Supply Chain

Checkmarx KICS Docker Repository and VS Code Extension Hijacked

Unknown threat actors hijacked the checkmarx/kics Docker Hub repository, overwriting official image tags to distribute malicious code via supply chain.

Runtime Rebel Intel
4 min read · Apr 22, 2026