Skip to main content
← All Articles

Tag

#Supply Chain Attack

226 articles

Advertisement

HIGH
Supply Chain

UNC1069 Leverages Axios NPM Supply Chain to Deploy WAVESHAPER.V2

North Korea-nexus UNC1069 compromised widely used Axios NPM package (v1.14.1, 0.30.4) by injecting plain-crypto-js to deploy WAVESHAPER.V2 backdoor across multiple OS.

Runtime Rebel Intel
8 min read · Apr 1, 2026
Axios NPM Compromise: Supply Chain Threat Analysis
HIGH
Supply Chain

Axios NPM Compromise: Supply Chain Threat Analysis

Analysis of the Axios NPM package compromise, a potential supply chain attack impacting JavaScript HTTP client library users, possibly by North Korean threat actors.

Runtime Rebel Intel
5 min read · Apr 1, 2026
HIGH
Supply Chain

Cisco Source Code Stolen: Trivy Supply Chain Attack Leads to Breach

Threat actors breached Cisco's dev environment using credentials from a Trivy supply chain attack, stealing proprietary and customer source code.

Runtime Rebel Intel
4 min read · Mar 31, 2026
CVE-2026-3502: TrueConf Zero-Day Exploited in Asia Gov Attacks
CRITICAL
Vulnerabilities

CVE-2026-3502: TrueConf Zero-Day Exploited in Asia Gov Attacks

TrueConf video conferencing zero-day [CVE-2026-3502] exploited to distribute tampered updates to Southeast Asian government networks in 'TrueChaos' campaign.

Runtime Rebel Intel
5 min read · Mar 31, 2026
HIGH
Supply Chain

Axios npm Package Hijacked: Cross-Platform Malware Distribution

Analysis of the Axios npm package hijack distributing remote access trojans to Linux, Windows, and macOS systems. Learn to protect your software supply chain.

Runtime Rebel Intel
5 min read · Mar 31, 2026
Axios Supply Chain Attack: RAT Found in Versions 1.14.1 and 0.30.4
HIGH
Supply Chain

Axios Supply Chain Attack: RAT Found in Versions 1.14.1 and 0.30.4

Malicious Axios versions 1.14.1 and 0.30.4 inject a cross-platform RAT via a fake dependency. Identify and remediate this npm supply chain threat now.

Runtime Rebel Intel
4 min read · Mar 31, 2026

Advertisement

HIGH
Supply Chain

TeamPCP Supply Chain Campaign: Databricks and AstraZeneca Impact

TeamPCP's supply chain campaign weaponizes security scanners for dual ransomware operations, impacting Databricks and AstraZeneca in a major breach.

Runtime Rebel Intel
4 min read · Mar 30, 2026
HIGH
Supply Chain

TeamPCP Supply Chain Campaign: Weaponized Scanners and PyPI Compromise

Analysis of the TeamPCP campaign transition to monetization following the Telnyx PyPI compromise and Vect ransomware partnership affecting security tools.

Runtime Rebel Intel
4 min read · Mar 28, 2026
HIGH
Supply Chain

TeamPCP Supply Chain: Checkmarx Wider Scope & LiteLLM PyPI Compromise

An update on the TeamPCP supply chain campaign details wider Checkmarx impact, LiteLLM PyPI compromise, and a CISA KEV entry.

Runtime Rebel Intel
5 min read · Mar 26, 2026
CRITICAL
Vulnerabilities

CVE-2026-33634: Aqua Trivy Embedded Malicious Code — Patch Now

CISA adds CVE-2026-33634, an Aqua Security Trivy Embedded Malicious Code Vulnerability, to KEV catalog due to active exploitation.

Runtime Rebel Intel
4 min read · Mar 26, 2026
HIGH
Supply Chain

TeamPCP Supply Chain Attacks Target Docker Hub, PyPI, and VS Code

TeamPCP expands supply chain attack tactics from GitHub Actions to Docker Hub, PyPI, and VS Code extensions, collaborating with the Lapsus$ hacking group.

Runtime Rebel Intel
4 min read · Mar 25, 2026
Checkmarx KICS & VS Code Plugin Targeted in Supply Chain Attack
HIGH
Supply Chain

Checkmarx KICS & VS Code Plugin Targeted in Supply Chain Attack

TeamPCP exploited Checkmarx KICS, VS Code plugins, and LiteLLM in a supply chain attack targeting code scanners and AI libraries, indicating expanding threats.

Runtime Rebel Intel
5 min read · Mar 25, 2026
HIGH
Supply Chain

LiteLLM PyPI Supply Chain Attack: TeamPCP Steals Credentials

TeamPCP compromised the LiteLLM PyPI package, backdooring it to steal credentials and auth tokens from hundreds of thousands of devices.

Runtime Rebel Intel
5 min read · Mar 25, 2026
TeamPCP Backdoors LiteLLM 1.82.7–1.82.8 via CI/CD Compromise
HIGH
Supply Chain

TeamPCP Backdoors LiteLLM 1.82.7–1.82.8 via CI/CD Compromise

TeamPCP threat actors compromised LiteLLM versions 1.82.7 and 1.82.8, deploying credential harvesters and Kubernetes lateral movement tools via CI/CD.

Runtime Rebel Intel
3 min read · Mar 24, 2026
Malicious GitHub OpenClaw Deployer Repos Deliver Trojans
HIGH
Supply Chain

Malicious GitHub OpenClaw Deployer Repos Deliver Trojans

Analysts uncover an AI-assisted campaign using over 300 poisoned GitHub repositories like OpenClaw Deployer to distribute infostealers to developers.

Runtime Rebel Intel
4 min read · Mar 24, 2026
npm Ghost Campaign: 7 Malicious Packages Steal Crypto Wallets
HIGH
Supply Chain

npm Ghost Campaign: 7 Malicious Packages Steal Crypto Wallets

ReversingLabs uncovers the Ghost campaign targeting developers with 7 malicious npm packages designed to exfiltrate cryptocurrency wallets and credentials.

Runtime Rebel Intel
3 min read · Mar 24, 2026
Trivy Supply Chain Attack Targets CI/CD Secrets in DevOps Workflows
HIGH
Supply Chain

Trivy Supply Chain Attack Targets CI/CD Secrets in DevOps Workflows

A supply chain attack leveraged the Trivy security tool to deploy an infostealer within CI/CD pipelines, compromising cloud credentials and sensitive secrets.

Runtime Rebel Intel
4 min read · Mar 24, 2026
CI/CD Pipeline Backdoors: Analyzing Recent Supply Chain Attacks
HIGH
Supply Chain

CI/CD Pipeline Backdoors: Analyzing Recent Supply Chain Attacks

Exploration of supply chain risks in CI/CD pipelines, IoT device exploitation trends, and the security implications of government data acquisition.

Runtime Rebel Intel
3 min read · Mar 23, 2026
Trivy Supply Chain Attack Spreads CanisterWorm via 47 npm Packages
HIGH
Supply Chain

Trivy Supply Chain Attack Spreads CanisterWorm via 47 npm Packages

Attackers compromise 47 npm packages using CanisterWorm, a self-propagating threat leveraging ICP canisters following a major Trivy supply chain attack.

Runtime Rebel Intel
3 min read · Mar 21, 2026
75 Trivy-Action GitHub Tags Hijacked in Supply Chain Attack
HIGH
Supply Chain

75 Trivy-Action GitHub Tags Hijacked in Supply Chain Attack

Attackers hijacked 75 tags in Aqua Security's Trivy GitHub Actions to exfiltrate CI/CD secrets, marking the second major breach in a single month.

Runtime Rebel Intel
3 min read · Mar 20, 2026
HIGH
Supply Chain

GlassWorm Supply Chain Attack: 400+ Malicious Repos Identified

The GlassWorm campaign hits GitHub, npm, and VSCode marketplaces with over 400 malicious repositories. Learn to detect and mitigate this supply chain threat.

Runtime Rebel Intel
4 min read · Mar 18, 2026
HIGH
Supply Chain

ForceMemo: Credential Theft Compromises Python Repositories

Researchers reveal ForceMemo, a campaign exploiting credentials stolen via GlassWorm to compromise hundreds of GitHub accounts and Python repositories.

Runtime Rebel Intel
3 min read · Mar 16, 2026
HIGH
Supply Chain

AppsFlyer Web SDK Hijacked to Deliver Crypto-Stealing Malware

AppsFlyer's Web SDK was compromised in a supply chain attack to steal cryptocurrency. Learn how to detect and mitigate this JavaScript injection threat.

Runtime Rebel Intel
3 min read · Mar 14, 2026
GlassWorm Abuses Open VSX Registry in Supply-Chain Attack
HIGH
Supply Chain

GlassWorm Abuses Open VSX Registry in Supply-Chain Attack

The GlassWorm campaign exploits transitive dependencies in 72 Open VSX extensions to deliver malicious loaders into developer environments.

Runtime Rebel Intel
3 min read · Mar 14, 2026