supply-chain Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks A new wave of Shai-Hulud supply chain attacks has impacted over 471 NPM and PyPI packages, utilizing variants named Miasma and Hades. The attacks, originating from TeamPCP, involve credential harvesting and self-replicat… SecurityWeek · Jun 9, 2026 High supply chainnpmpypi
supply-chain Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer A new supply chain attack, dubbed Hades, is leveraging the Miasma campaign to compromise 37 PyPI packages, including those used in bioinformatics and computational biology. The attack utilizes a malicious setup.pth file… The Hacker News · Jun 9, 2026 High RUsupply-chainpythoncredential-stealing
supply-chain New Shai-Hulud attack trojanizes 19 science-focused PyPI packages A new supply-chain attack, dubbed Shai-Hulud, has compromised 19 popular Python packages hosted on the PyPI, distributing a trojan designed to steal developer secrets. The malware leverages a chain of execution to downlo… BleepingComputer · Jun 8, 2026 High supply-chainpythonsecrets
supply-chain TeamPCP Supply Chain Campaign: Activity Through 2026-06-07, (Mon, Jun 8th) This report details the ongoing TeamPCP supply chain campaign, which has recently seen increased activity and expanded impact. CISA has formally acknowledged and addressed the campaign, adding vulnerabilities to its Know… SANS Internet Storm Center · Jun 8, 2026 High CVE-2026-45321CVE-2026-48027CVE-2026-8398USsupply chainnpmgithub
supply-chain 'Hades' Campaign Against PyPI Puts New Spin on Shai-Hulud A new wave of attacks, dubbed the 'Hades' campaign, has targeted the Python Package Index (PyPI) with a variant of the Shai-Hulud worm. This campaign involved compromising 37 PyPI wheels and 19 code packages, utilizing a… Dark Reading · Jun 8, 2026 High USsupply-chainpythonopen-source
supply-chain VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks Microsoft has announced that Visual Studio Code (VS Code) will apply a two-hour delay before extensions for the integrated development environment (IDE) are updated automatically to a newer version in an attempt to tackl… The Hacker News · Jun 8, 2026
supply-chain Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack A sophisticated supply chain attack, dubbed Miasma, has compromised 73 Microsoft GitHub repositories, including several within the Azure and Microsoft organizations. The attack leverages a re-compromised PyPI package, du… The Hacker News · Jun 6, 2026 High supply chaingithubopen source
supply-chain IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks A sophisticated supply chain attack targeting the npm ecosystem has resulted in the deployment of both IronWorm, a Rust-based information stealer with self-replicating capabilities, and a new variant of the Miasma worm.… The Hacker News · Jun 5, 2026 High USsupply-chainnpmrust
supply-chain Rust-Written IronWorm Hits NPM Supply Chain A new Rust-written malware campaign, dubbed "IronWorm," is targeting developers through compromised npm publishing workflows, stealing credentials like API keys and cloud credentials to spread across the software supply… Dark Reading · Jun 4, 2026 High USsupply chaincredential theftebpf
supply-chain Hola Browser for Windows compromised to deliver cryptominer The Windows version of the Hola Browser has been compromised in a supply chain attack that delivered an undeclared executable identified by researchers as a cryptocurrency miner. BleepingComputer · Jun 4, 2026
supply-chain New IronWorm malware hits 36 packages in npm supply-chain attack A new supply-chain attack leveraging the IronWorm malware has compromised 36 npm packages, targeting developers and CI environments with infostealer capabilities. The malware utilizes stolen credentials and a sophisticat… BleepingComputer · Jun 4, 2026 High supply chainnpmrust
supply-chain Red Hat removes tainted packages after software pipeline compromise Red Hat removed numerous software packages from its distribution pipeline after a compromised GitHub account was used to distribute credential-stealing malware. The attack, utilizing a variant of the Mini Shai-Hulud worm… The Record · Jun 2, 2026 High NOUKsupply chaingithubmalware
supply-chain Supply Chain Attack Hits 32 Red Hat NPM Packages Hackers published 96 malicious package versions, injected with a credential-stealing worm similar to Mini Shai-Hulud. The post Supply Chain Attack Hits 32 Red Hat NPM Packages appeared first on SecurityWeek . SecurityWeek · Jun 2, 2026
supply-chain Red Hat npm packages compromised to steal developer credentials A supply-chain attack targeting Red Hat npm packages resulted in the distribution of a new variant of the Shai-Hulud credential-stealing malware, dubbed 'Miasma'. The attackers compromised a Red Hat employee's GitHub acc… BleepingComputer · Jun 1, 2026 High USsupply chaincredential theftgithub
supply-chain Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm A new supply chain attack, dubbed Miasma, has compromised Red Hat npm packages, utilizing a self-propagating worm to steal credentials and secrets from developer machines. The attack, leveraging techniques similar to the… The Hacker News · Jun 1, 2026 High USsupply chain attackcredential theftgithub actions
supply-chain OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack A supply chain attack targeting OpenAI Codex developers has been discovered through a malicious npm package named ‘codexui-android’. The package, developed by ‘friuns’ (Igor Levochkin) and promoted by ‘BrutalStrike’, sil… The Hacker News · Jun 1, 2026 High USsupply chainauthenticationtokens
supply-chain Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets A malicious NuGet package, 'Sicoob.Sdk,' disguised as a C# SDK for Sicoob, Brazil's largest cooperative financial system, was discovered to be stealing client IDs and PFX certificates. This allowed unauthorized access to… The Hacker News · May 29, 2026 High BRsupply-chaincredentialsbanking
supply-chain Supply Chain Compromises Impact Nx Console and GitHub Repositories CISA is responding to multiple supply chain attacks targeting developer ecosystems, specifically CI/CD pipelines. A malicious Nx Console VS Code extension compromised a GitHub employee, leading to data exfiltration, and… CISA Advisories · May 28, 2026 High CVE-2026-48027supply chainci/cdgithub
supply-chain Glassworm botnet disrupted after resilient C2 infrastructure takedown The Glassworm botnet, a supply-chain threat targeting developers, has been significantly disrupted following a coordinated takedown of its resilient command-and-control infrastructure. The botnet utilized a complex archi… BleepingComputer · May 27, 2026 High supply-chainbotnetc2
supply-chain ‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems The ‘SymJack’ attack leverages AI coding agents as a supply chain delivery mechanism, exploiting developer trust in automation to inject malicious code into CI pipelines. Attackers gain control by compromising coding age… SecurityWeek · May 27, 2026 High USaicoding agentssupply chain