Skip to main content
← All Articles

Tag

#Supply Chain Attack

226 articles

Advertisement

HIGH
Malware

Malicious Crypto Wallets Infiltrate China's Apple App Store

26 fake cryptocurrency wallet apps infiltrated China's Apple App Store, impersonating popular brands to steal seed phrases and drain user funds.

Runtime Rebel Intel
4 min read · Apr 21, 2026
Vercel Breach: Third-Party Context.ai Compromise Leads to Data Exposure
MEDIUM
Supply Chain

Vercel Breach: Third-Party Context.ai Compromise Leads to Data Exposure

Vercel reports a security incident where a compromised third-party AI tool, Context.ai, allowed attackers to access internal Google Workspace accounts.

Runtime Rebel Intel
4 min read · Apr 20, 2026
TeamPCP Supply Chain Attack: From Credential Theft to Payroll Fraud
HIGH
Supply Chain

TeamPCP Supply Chain Attack: From Credential Theft to Payroll Fraud

TeamPCP leverages supply chain attacks to compromise trusted software, facilitating large-scale credential harvesting, logistics theft, and payroll fraud.

Runtime Rebel Intel
4 min read · Apr 15, 2026
HIGH
Supply Chain

Trojanized CPU-Z and HWMonitor Distributed via CPUID Site Hack

Russian-speaking threat actors compromised the CPUID website to distribute STX RAT through trojanized versions of CPU-Z and HWMonitor diagnostic tools.

Runtime Rebel Intel
4 min read · Apr 13, 2026
CPUID Supply Chain Attack: Trojanized CPU-Z Distributes STX RAT
HIGH
Supply Chain

CPUID Supply Chain Attack: Trojanized CPU-Z Distributes STX RAT

Attackers compromised the CPUID website to distribute malicious versions of CPU-Z and HWMonitor containing the STX RAT during a 24-hour breach window.

Runtime Rebel Intel
3 min read · Apr 12, 2026
HIGH
Threat Intel

Windows Zero-Day, Stryker Breach, & Mac Stealer Malware: Mitigating Diverse Threats

Analysis of a Windows zero-day, cyberattacks on Stryker and Jones Day, a China supercomputer hack, and new Mac stealer malware.

Runtime Rebel Intel
6 min read · Apr 10, 2026

Advertisement

Smart Slider 3 Pro 3.5.1.35 Backdoor via Supply Chain Attack
HIGH
Supply Chain

Smart Slider 3 Pro 3.5.1.35 Backdoor via Supply Chain Attack

Nextend's Smart Slider 3 Pro version 3.5.1.35 was compromised via a supply chain attack. Learn how to identify and remediate the backdoor today.

Runtime Rebel Intel
3 min read · Apr 10, 2026
HIGH
Supply Chain

TeamPCP Supply Chain Campaign: Cisco Source Code Stolen, UNC6780 Activity

Analysis of the TeamPCP supply chain campaign, including the theft of Cisco source code and over 1,000 compromised SaaS environments tracked by Google GTIG as UNC6780.

Runtime Rebel Intel
4 min read · Apr 9, 2026
HIGH
Threat Intel

UNC6783 Leverages BPOs to Steal Corporate Zendesk Tickets

New threat actor UNC6783 targets Business Process Outsourcing (BPO) providers to gain access to client Zendesk support tickets, risking sensitive data.

Runtime Rebel Intel
4 min read · Apr 9, 2026
HIGH
Malware

Magecart Skimmer Hides in Pixel-Sized SVG on Magento Stores

A sophisticated Magecart campaign targets nearly 100 Magento stores, concealing credit card-stealing JavaScript within tiny, pixel-sized SVG images.

Runtime Rebel Intel
5 min read · Apr 9, 2026
HIGH
Supply Chain

litellm 1.82.8 Supply Chain Compromise via Malicious .pth File

Security analysis of a supply chain compromise in litellm 1.82.8 on PyPI, where a malicious .pth file enables automatic code execution on Python startup.

Runtime Rebel Intel
4 min read · Apr 8, 2026
North Korean Hackers Distribute 1,700 Malicious Packages via npm and PyPI
HIGH
Supply Chain

North Korean Hackers Distribute 1,700 Malicious Packages via npm and PyPI

North Korean threat actors expand the Contagious Interview campaign, deploying 1,700 malicious packages across npm, PyPI, Go, and Rust ecosystems.

Runtime Rebel Intel
3 min read · Apr 8, 2026
HIGH
Supply Chain

Snowflake Data Theft Via SaaS Integrator Breach: Mitigation

Snowflake customers face data theft due to compromised third-party SaaS integrators and stolen authentication tokens. Learn to secure integrations and detect compromise.

Runtime Rebel Intel
5 min read · Apr 7, 2026
Axios Attack: Industrialized Social Engineering on NPM Maintainers
HIGH
Supply Chain

Axios Attack: Industrialized Social Engineering on NPM Maintainers

An analysis of the Axios NPM package attack reveals advanced, scaled social engineering campaigns targeting open-source maintainers, elevating supply chain risk.

Runtime Rebel Intel
4 min read · Apr 7, 2026
AI-Assisted Supply Chain Attack Targets GitHub Misconfigurations
MEDIUM
Supply Chain

AI-Assisted Supply Chain Attack Targets GitHub Misconfigurations

Analysis of the AI-assisted PRT-scan supply chain attack targeting GitHub misconfigurations. Learn about automated threats and securing repositories.

Runtime Rebel Intel
4 min read · Apr 7, 2026
HIGH
Supply Chain

Guardarian Users Targeted via 36 Malicious Strapi npm Packages

Analysis of a supply chain attack involving 36 malicious npm packages posing as Strapi plugins to target Guardarian users and harvest sensitive credentials.

Runtime Rebel Intel
4 min read · Apr 6, 2026
HIGH
Supply Chain

European Commission AWS Breach: Trivy Supply Chain Attack Analysis

The European Commission confirms a 300GB data breach in its AWS environment linked to a Trivy supply chain attack. Learn about the impact and mitigations.

Runtime Rebel Intel
4 min read · Apr 4, 2026
HIGH
Supply Chain

TeamPCP Supply Chain: CERT-EU Confirms Cloud Breach, 1000+ SaaS Environments Affected

CERT-EU confirms European Commission cloud breach via TeamPCP supply chain campaign. Mandiant identifies over 1,000 compromised SaaS environments.

Runtime Rebel Intel
5 min read · Apr 3, 2026
TeamPCP Supply Chain Attacks Escalate Amidst Hacker Infighting
HIGH
Threat Intel

TeamPCP Supply Chain Attacks Escalate Amidst Hacker Infighting

Runtime Rebel details how TeamPCP's supply chain attacks are leading to breaches, with ShinyHunters and Lapsus$ adding to the chaos.

Runtime Rebel Intel
4 min read · Apr 3, 2026
UNC1069 Social Engineering Leads to Axios npm Supply Chain Compromise
HIGH
Supply Chain

UNC1069 Social Engineering Leads to Axios npm Supply Chain Compromise

Runtime Rebel details how North Korean threat actor UNC1069 leveraged targeted social engineering against an Axios npm package maintainer, leading to a critical supply…

Runtime Rebel Intel
4 min read · Apr 3, 2026
HIGH
Malware

Fake GitHub Repositories Deliver Vidar Infostealer via Claude Leak

Threat actors are exploiting the Claude Code leak, deploying fake GitHub repositories to distribute Vidar infostealer malware, targeting unsuspecting developers and…

Runtime Rebel Intel
4 min read · Apr 3, 2026
HIGH
Supply Chain

Mercor Hit by LiteLLM Supply Chain Attack – Lapsus$ Claims 4TB Data Theft

AI recruiting firm Mercor is investigating a LiteLLM supply chain attack, with Lapsus$ claiming to have stolen 4TB of sensitive data.

Runtime Rebel Intel
4 min read · Apr 2, 2026
HIGH
Supply Chain

TeamPCP Supply Chain Campaign: First Victim, Cloud Enumeration, Ransomware

Detailed analysis of TeamPCP supply chain campaign, covering the first confirmed victim, post-compromise cloud enumeration tactics, and dual ransomware operations.

Runtime Rebel Intel
4 min read · Apr 1, 2026
HIGH
Supply Chain

Axios NPM Supply Chain Attack Bypasses GitHub Actions CI/CD

A sophisticated supply chain attack targeted the Axios NPM package, leveraging a compromised token to bypass GitHub Actions CI/CD and deploy malicious versions.

Runtime Rebel Intel
4 min read · Apr 1, 2026