supply-chain SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines A sophisticated supply chain attack, dubbed SleeperGem, has been targeting Ruby developers through three previously dormant malicious RubyGems packages. These packages, including a fake Git Credential Manager, were updat… The Hacker News · Jul 20, 2026 High rubysupply chainmalware
supply-chain Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT A sophisticated software supply chain attack, dubbed ViteVenom, is leveraging a blockchain-based command-and-control (C2) infrastructure to deliver a remote access trojan (RAT) targeting Vite frontend developers. The att… The Hacker News · Jul 17, 2026 High supply chainblockchainc2
supply-chain E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants The European Commission has ordered Google to allow rival AI assistants on Android to access device features like the microphone, camera, and screen, effectively dismantling Google's control over these functionalities. T… The Hacker News · Jul 17, 2026 High aiandroiddata-sharing
supply-chain Risk Ledger Raises $32 Million in Series B Funding Risk Ledger, a UK-based supply chain security firm, secured $32.3 million in Series B funding to expand its network and enhance its AI-powered risk intelligence platform. This investment will allow them to grow their use… SecurityWeek · Jul 17, 2026 Info GBsupply chaincybersecurityrisk management
supply-chain The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) The npm ecosystem experienced a critical inflection point in September 2025 with the emergence of the Shai-Hulud worm, marking a shift from nuisance attacks to a high-consequence threat landscape. Since then, Unit 42 has… Palo Alto Unit 42 · Jul 15, 2026 High NLsupply chainnpmgithub
supply-chain Cyberattack on Japan's largest cold-chain operator disrupts KFC, supermarket supplies A cyberattack on Japan's largest cold-chain logistics company, Nichirei Logistics Group, has severely disrupted the country's food supply chain, impacting KFC restaurants, supermarkets, and various food manufacturers. Th… The Record · Jul 15, 2026 High JPcyberattacksupply chainjapan
supply-chain Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware A sophisticated supply-chain attack leveraging compromised npm packages has delivered a multi-stage botnet loader, Miasma, to numerous developers. The attacker exploited a GitHub Actions release pipeline to inject malici… The Hacker News · Jul 15, 2026 High supply chainnpmgithub actions
supply-chain Multiple Jscrambler Packages Impacted by Supply Chain Attack A supply chain attack targeting Jscrambler’s NPM package led to the distribution of malicious versions containing malware designed to steal sensitive information from developer and cloud environments. The attack exploite… SecurityWeek · Jul 14, 2026 High npmsupply chainmalware
supply-chain Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install A malicious npm package, jscrambler 8.14.0, was released with a hidden infostealer that silently dropped and executed during installation. The package, pushed by a compromised account, included a Rust-based stealer targe… The Hacker News · Jul 11, 2026 High npmsupply-chainrust
supply-chain Network of 200 GitHub Repositories Used for Malware Infection A threat actor, linked to previous activity associated with the ‘ischhfd83’ email address, has created a network of over 200 GitHub repositories delivering Windows malware through a Go module disguised as a DNS scanning… SecurityWeek · Jul 10, 2026 High supply chaingithubmalware
supply-chain npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk GitHub has released npm 12, significantly bolstering supply chain security by disabling install scripts and deprecating granular access tokens (GATs). These changes restrict automated script execution and limit the abili… The Hacker News · Jul 9, 2026 Medium npmsupply chainsecurity
supply-chain North Korean Hackers Target Open Source Developers in Supply Chain Attacks North Korean hackers, linked to the Contagious Interview operation, are engaging in a sophisticated supply chain attack targeting open-source developers. They are leveraging compromised GitHub repositories and malicious… SecurityWeek · Jul 6, 2026 High KRsupply-chaingithubopen-source
supply-chain Polymarket customers lose $3 million in supply-chain attack Polymarket says it will fully reimburse customers who lost an estimated $3 million after hackers injected a malicious script into the platform's frontend following a breach at a third-party vendor. BleepingComputer · Jun 26, 2026
supply-chain Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack A sophisticated supply chain attack, spearheaded by the Miasma malware family (linked to Mini Shai-Hulud and Hades), is targeting npm packages and GitHub Actions workflows. The attackers are leveraging compromised npm pa… The Hacker News · Jun 26, 2026 High RUsupply chainnpmgithub actions
supply-chain Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks A new vulnerability, dubbed 'Cordyceps,' has been discovered in CI/CD workflows, allowing unauthorized access and control over hundreds of GitHub repositories across major tech companies. The flaw stems from overly permi… The Hacker News · Jun 24, 2026 Critical cicdsupply chaingithub
supply-chain Exploitable CI/CD Vulnerabilities Expose Millions of Repositories to Hijacking A new vulnerability, dubbed ‘Cordyceps,’ has been identified within CI/CD workflows across numerous open-source projects, allowing unauthorized access and control over developer repositories. The flaws, primarily found i… SecurityWeek · Jun 24, 2026 High ci/cdsupply chaingithub actions
supply-chain OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat This report details a significant supply chain attack leveraging OpenClaw’s Skill Marketplace, highlighting the emerging threat of AI agentic software. Malicious skills, including infostealers and evasion techniques, wer… Palo Alto Unit 42 · Jun 23, 2026 High USaiagenticsupply chain
supply-chain 'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows A new vulnerability, dubbed "Cordyceps," is targeting CI/CD workflows across several open-source projects, including Azure Sentinel, Doris, Workers SDK, and Black. Attackers can exploit weak automated processes within th… Dark Reading · Jun 23, 2026 High cicdsupply chainpull requests
supply-chain GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns GitHub is implementing a security update to its "actions/checkout" action to mitigate a common supply chain attack vector. The update, effective June 18, 2026, will block the execution of malicious code from untrusted fo… The Hacker News · Jun 23, 2026 High supply-chaingithubactions
supply-chain ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack A supply chain attack compromised multiple WordPress plugins from ShapedPlugin, injecting backdoor code into Pro plugin releases distributed through official update channels. The malicious plugins, affecting versions of… The Hacker News · Jun 22, 2026 Critical CVE-2026-49777CVE-2026-10735wordpresssupply chainbackdoor