supply chain attack

BigCommerce Data Stolen via Ribon Apps Hack

BigCommerce Data Stolen via Ribon Apps Hack 2026-09-22 at 20:58 By Ionut Arghire The attackers used a compromised BigCommerce application key held by Ribon to access customer data. The post BigCommerce Data Stolen via Ribon Apps Hack appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

BigCommerce Data Stolen via Ribon Apps Hack Read More »

Malicious B-tree NPM Package Accumulates Millions of Downloads

Malicious B-tree NPM Package Accumulates Millions of Downloads 2026-09-22 at 14:33 By Ionut Arghire Posing as the legitimate sorted-btree package, indexed-btree hides a malware trigger in its prototype method. The post Malicious B-tree NPM Package Accumulates Millions of Downloads appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Malicious B-tree NPM Package Accumulates Millions of Downloads Read More »

Rust Team Members and Popular Crate Owners Targeted via Video Calls

Rust Team Members and Popular Crate Owners Targeted via Video Calls 2026-09-21 at 14:57 By Eduard Kovacs It’s unclear if the attacks are part of previous campaigns against Rust, but the techniques used by the attackers match those used by North Korea. The post Rust Team Members and Popular Crate Owners Targeted via Video Calls […]

Rust Team Members and Popular Crate Owners Targeted via Video Calls Read More »

CrowdSec Confirms Source Code Stolen in Supply Chain Attack

CrowdSec Confirms Source Code Stolen in Supply Chain Attack 2026-09-21 at 13:55 By Ionut Arghire The cybersecurity firm believes the data breach was the result of the May 2026 TanStack supply chain attack. The post CrowdSec Confirms Source Code Stolen in Supply Chain Attack appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

CrowdSec Confirms Source Code Stolen in Supply Chain Attack Read More »

Brevo Supply Chain Attack Injects Malware Into 100,000 Websites

Brevo Supply Chain Attack Injects Malware Into 100,000 Websites 2026-09-18 at 12:46 By Ionut Arghire Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts. The post Brevo Supply Chain Attack Injects Malware Into 100,000 Websites appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Brevo Supply Chain Attack Injects Malware Into 100,000 Websites Read More »

Rust Supply Chain Attack Linked to North Korean Hackers

Rust Supply Chain Attack Linked to North Korean Hackers 2026-08-21 at 12:23 By Ionut Arghire Hackers pushed a poisoned arrayref version that added a dependency to fetch a malicious payload from a remote server. The post Rust Supply Chain Attack Linked to North Korean Hackers appeared first on SecurityWeek. This article is an excerpt from […]

Rust Supply Chain Attack Linked to North Korean Hackers Read More »

Trivy, Not LiteLLM Behind the 2,500 Org Compromise

Trivy, Not LiteLLM Behind the 2,500 Org Compromise 2026-08-14 at 14:35 By Ionut Arghire Over 95% of the affected companies were exposed before the malicious LiteLLM packages were published. The post Trivy, Not LiteLLM Behind the 2,500 Org Compromise appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Trivy, Not LiteLLM Behind the 2,500 Org Compromise Read More »

Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack

Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack 2026-08-05 at 11:56 By Ionut Arghire The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials. The post Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack appeared first on SecurityWeek. This article is an […]

Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack Read More »

Multiple Jscrambler Packages Impacted by Supply Chain Attack

Multiple Jscrambler Packages Impacted by Supply Chain Attack 2026-07-14 at 12:04 By Ionut Arghire A threat actor poisoned several Jscrambler NPM package versions to drop a cross-platform credential stealer. The post Multiple Jscrambler Packages Impacted by Supply Chain Attack appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Multiple Jscrambler Packages Impacted by Supply Chain Attack Read More »

North Korean Hackers Target Open Source Developers in Supply Chain Attacks 

North Korean Hackers Target Open Source Developers in Supply Chain Attacks  2026-07-06 at 16:11 By Ionut Arghire The PolinRider campaign has compromised more than 100 legitimate open source packages and repositories to deliver a backdoor and information stealer to developers. The post North Korean Hackers Target Open Source Developers in Supply Chain Attacks  appeared first […]

North Korean Hackers Target Open Source Developers in Supply Chain Attacks  Read More »

Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks

Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks 2026-06-30 at 16:00 By Kevin Townsend Decades-old Bash shell tricks can bypass safeguards in most open source AI coding agents, potentially turning malicious repositories into supply chain attack vectors. The post Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks appeared first […]

Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks Read More »

More Klue Breach Victims Identified as Hackers Get Hacked

More Klue Breach Victims Identified as Hackers Get Hacked 2026-06-26 at 18:01 By Ionut Arghire Roughly two dozen companies have notified their customers of the Klue-Salesforce incident impact. The post More Klue Breach Victims Identified as Hackers Get Hacked appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

More Klue Breach Victims Identified as Hackers Get Hacked Read More »

North Korean Hackers Blamed for Mastra NPM Supply Chain Attack

North Korean Hackers Blamed for Mastra NPM Supply Chain Attack 2026-06-22 at 14:10 By Ionut Arghire A malicious dependency the attackers added to over 140 Mastra packages fetches a payload targeting cryptocurrency extensions. The post North Korean Hackers Blamed for Mastra NPM Supply Chain Attack appeared first on SecurityWeek. This article is an excerpt from […]

North Korean Hackers Blamed for Mastra NPM Supply Chain Attack Read More »

More Cybersecurity Firms Disclose Impact From Klue Hack

More Cybersecurity Firms Disclose Impact From Klue Hack 2026-06-22 at 12:03 By Ionut Arghire HackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk, and Tanium are among the affected Klue customers. The post More Cybersecurity Firms Disclose Impact From Klue Hack appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

More Cybersecurity Firms Disclose Impact From Klue Hack Read More »

Cybersecurity Firms Impacted by Klue Supply Chain Attack

Cybersecurity Firms Impacted by Klue Supply Chain Attack 2026-06-19 at 12:19 By Ionut Arghire The hackers exfiltrated data from Salesforce instances of Klue customers, such as Huntress and Recorded Future. The post Cybersecurity Firms Impacted by Klue Supply Chain Attack appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Cybersecurity Firms Impacted by Klue Supply Chain Attack Read More »

Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages

Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages 2026-06-16 at 13:51 By Ionut Arghire Arch Linux suspended account registrations in response to the wave of malicious packages being uploaded to AUR. The post Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages Read More »

Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks

Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks 2026-06-09 at 15:21 By Ionut Arghire The most recent variants of the self-propagating attacks are named Miasma and Hades. The post Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks appeared first on SecurityWeek. This article is an excerpt from […]

Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks Read More »

Supply Chain Attack Hits 32 Red Hat NPM Packages

Supply Chain Attack Hits 32 Red Hat NPM Packages 2026-06-02 at 15:46 By Ionut Arghire Hackers published 96 malicious package versions, injected with a credential-stealing worm similar to Mini Shai-Hulud. The post Supply Chain Attack Hits 32 Red Hat NPM Packages appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Supply Chain Attack Hits 32 Red Hat NPM Packages Read More »

Laravel-Lang Packages Poisoned for Malware Delivery

Laravel-Lang Packages Poisoned for Malware Delivery 2026-05-25 at 15:31 By Ionut Arghire Published within a 15-minute window, the malicious tags introduced backdoors to exfiltrate CI secrets. The post Laravel-Lang Packages Poisoned for Malware Delivery appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Laravel-Lang Packages Poisoned for Malware Delivery Read More »

Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack

Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack 2026-05-25 at 10:56 By Ionut Arghire Fake automated commits injected GitHub Actions workflows containing payloads to steal credentials, CI secrets, keys, and tokens. The post Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack appeared first on SecurityWeek. This article is an excerpt from […]

Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack Read More »

Scroll to Top