HeadFlash

Topic · 39 stories

Supply chain attacks: compromised software, news

Edited by Marcin Rybak

This edition was produced with artificial intelligence. Text and voice are generated automatically.

Timeline

  1. Google analyst spent months inside TeamPCP supply-chain gang Security
  2. Malicious npm package hides loader in runtime code Security
  3. Compromised Packagist themes serve iOS exploit chain Security
  4. EndlessDoors backdoor found in Zbtlink router firmware gives Chinese server root control Security
  5. Shai-Hulud npm worm returns with identical payload, bypassing new scanning Security
  6. North Korea Trojanized HAProxy in South Korea, Turning SSL Termination Into Wiretap Security
  7. Poisoned Scanner Compromise Hits 2,500 Companies via AI Supply-Chain Package Security
  8. Hackers Abuse npm Mirrors to Host Phishing Pages on Legitimate Domains Security
  9. UK Proposes New Powers to Ban Essential Services from Buying Risky Tech Vendors Security
  10. Supply-Chain Attack Infects Android Car Head Units With Proxy Botnet Malware Security
Show older (29 stories)
  1. Kimi Desktop Updater Installs Unverified Code from Mutable CDN Security
  2. Extension Resurrection: Shadow dependencies in IDE packs open supply-chain attack vector Security
  3. LiteLLM supply chain attack compromises thousands of enterprises, 153GB of secrets leaked Security
  4. Hidden Backdoor in Zbtlink Routers Opens Root Access on 100,000 Devices Security
  5. npm Attack Uses Provenance Attestations as Camouflage in 400+ Package Supply Chain Breach Security
  6. Head Mare Breaches TrueConf Servers to Trojanize Client Installers with Backdoors Security
  7. ENDLESSDOORS backdoor found in Chinese routers sold under multiple brand names Security
  8. Persistent ‘EndlessDoors’ Backdoor Found in Over 20 Zbtlink Router Models Security
  9. ChainDrop worm compromises 1,300+ npm packages Security
  10. Arch Linux freezes AUR adoption as Tor-backed Rust infostealer hits third wave Security
  11. Amazon links NPM supply chain attacks to North Korean hacker group Security
  12. Amazon Attributes Debug, Chalk, and Axios npm Attacks to North Korean Hackers Security
  13. New ‘hallusquatting’ attack exploits AI coding assistants to install malware AI
  14. FakeGit Campaign Uses 7,600 GitHub Repos to Distribute Malware Security
  15. Cisco Sounds Alarm Over New Russian Malware Campaign Hitting Firms in US and Europe Security
  16. Slopsquatting Exploits LLM Hallucinations for Software Supply Chain Attacks AI
  17. HalluSquatting Exploits AI Hallucinations to Build Agentic Botnets Security
  18. Operation Muck and Load Uses 200 GitHub Repositories to Deliver Malware Security
  19. Two-Click RCE in Meccha Chameleon Exploits Steam Workshop Security
  20. North Korean npm Packages Impersonate Rollup Polyfill Tools Security
  21. AI Coding Agents Bypass Package Verification, Fueling Supply Chain Attacks AI
  22. Polymarket Loses $3.1M to Frontend Hack Amid CFTC Investigation Security
  23. 15 Malicious JetBrains Plugins Stole AI API Keys from 70,000 Developers Security
  24. LastPass Breached via Klue Supply-Chain Attack: Customer Data Stolen, Vaults Intact Privacy
  25. LastPass Breached via Klue Supply-Chain Attack Security
  26. Cordyceps: Malicious Pull Requests Compromise Developer Workflows Security
  27. Steam’s Wallpaper Engine Workshop Hijacked with Malicious Wallpapers Security
  28. Attackers Hijacked Over 1,500 Arch Linux Packages in Supply Chain Attack Security
  29. Microsoft GitHub Repositories Compromised with Credential-Stealing Malware Security