supply-chain Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more Two men from Western Australia have been charged in connection with TeamPCP, a cybercriminal group responsible for a global supply-chain hacking campaign that targeted over 1000 organizations, including OpenAI and the European Commission. The group used a self-propagating worm, Shai-Hulud, to steal data and credentials… Graham Cluley · 2d ago High AUsupply chainopen sourcemalware
threat-intel TeamPCP : deux suspects arrêtés en Australie TeamPCP, a sophisticated cybercrime group, emerged in late 2025 and escalated to supply chain attacks in early 2026. Two suspects were arrested in Australia in August 2026, linked to a global operation involving data th… ZATAZ · 3d ago High AUsupply chainransomwarevulnerability
threat-intel Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks Australian authorities have charged two men linked to the cybercrime group TeamPCP, allegedly responsible for a widespread supply chain attack targeting over 1,000 organizations globally. The group exploited compromised… The Hacker News · 3d ago High AUsupply chaincredential theftopen source
threat-intel Two Alleged ‘TeamPCP’ Hackers Arrested in Australia Two men, believed to be members of the Australian cybercrime group TeamPCP, have been arrested in Western Australia. TeamPCP is a prolific group responsible for a long-running series of software supply chain attacks, emb… Krebs on Security · 3d ago High AUSOsupply-chaincybercrimeopen-source
threat-intel 24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages Researchers at OX Security discovered a campaign utilizing 24 npm packages to host fake Cloudflare CAPTCHA pages via unpkg mirrors, redirecting users to phishing infrastructure. The threat actors are leveraging npm's inf… The Hacker News · 5d ago High npmphishingmalware
supply-chain Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain Unit 42 research reveals a significant shift in supply chain attacks, with attackers now targeting the tools and processes developers use throughout the software development lifecycle (SDLC). The ChainDrop npm worm exemp… Palo Alto Unit 42 · Aug 21, 2026 High CVE-2024-3094supply chainnpmci/cd
threat-intel 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2 A new AI-powered Linux backdoor, RedC2 4.0, is being distributed through malicious npm packages, significantly lowering the barrier to entry for attackers. The framework, developed and sold by Red Offsec, offers advanced… The Hacker News · Aug 21, 2026 High npmlinuxbackdoor
supply-chain ChainDrop worm crawls into npm supply chain, evades standard defenses A ChainDrop worm is exploiting vulnerabilities within the npm package manager supply chain, bypassing standard security defenses. This allows attackers to inject malicious code into legitimate packages, potentially compr… The Register · Aug 15, 2026 High supply-chainnpmvulnerability
threat-intel Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials A malicious Microsoft Visual Studio Code extension named Solidity Pro has been identified as a sophisticated information stealer, capable of harvesting a wide range of sensitive data from users’ systems, including crypto… The Hacker News · Aug 10, 2026 High vscodeextensionmalware
threat-intel Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer A sophisticated campaign involving nearly 800 malicious npm packages has been deployed to deliver cross-platform malware – a Remote Access Trojan (RAT) and infostealer – targeting Windows, macOS, and Linux systems. The p… The Hacker News · Aug 7, 2026 High RUnpmsupply chainmalware
threat-intel ChainDrop: Inside a Self-Propagating npm Worm A self-propagating npm worm, nicknamed ChainDrop, has infected over 400 packages, collectively downloaded hundreds of millions of times weekly. Developed by a threat actor, the worm steals sensitive data including cloud… Palo Alto Unit 42 · Aug 6, 2026 High npmgithubcredential theft
threat-intel ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories This week's 'ThreatsDay' bulletin highlights a diverse range of security threats, including a China-linked telecom risk, a multi-stage phishing attack leveraging ClickOnce files, a supply chain attack involving 846 softw… The Hacker News · Aug 6, 2026 High CVE-2025-21079CVE-2025-58486CVE-2026-25177CHUSsupply-chainmalwarephishing
supply-chain Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th) A sophisticated supply-chain attack leveraging compromised npm packages (keyv and cacheable) has been active since August 4th, 2026. Attackers exploited a vulnerability to inject malicious code into widely used libraries… SANS Internet Storm Center · Aug 5, 2026 High supply-chainnpmcredential theft
threat-intel Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addresses North Korean hackers are utilizing a new, more sophisticated command-and-control (C2) technique called NullReceiver to evade detection. Instead of embedding a C2 address in a transaction or using a smart contract, NullRe… The Hacker News · Aug 5, 2026 High KPc2ethereumnpm
threat-intel Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data A cluster of 77 malicious extensions masquerading as legitimate developer tools on the Open VSX marketplace have been discovered. These extensions, dubbed ‘evil twins,’ exfiltrate sensitive developer data, including work… The Hacker News · Aug 5, 2026 High supply chainmalwareopen vsx
supply-chain Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack A sophisticated supply chain attack, dubbed ChainDrop, has infected over 2,200 malicious versions of 440 NPM packages, resulting in over 500 million weekly downloads. The attack began with a compromised GitHub account an… SecurityWeek · Aug 5, 2026 High supply chainnpmgithub
threat-intel Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks A sophisticated npm worm, linked to the Keyv vulnerability and attributed to the Shai-Hulud threat actor family, has spread across hundreds of packages, injecting credential-stealing and malicious code. The worm leverage… The Hacker News · Aug 4, 2026 High npmsupply-chaincredential-stealing
threat-intel 18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users A sophisticated supply chain attack targeting Chinese-speaking developers using Alibaba tools has been discovered. Researchers found a set of malicious npm packages, including wrappers mimicking private Alibaba packages,… The Hacker News · Aug 3, 2026 High CHsupply chainmalwarenpm
threat-intel In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research Several cybersecurity incidents and vulnerabilities were reported this week, ranging from a data breach at the UK Department for Education to supply-chain attacks linked to North Korea. OpenAI released a new open-source… SecurityWeek · Jul 31, 2026 High UNNOsupply-chainvulnerabilitycryptanalysis
threat-intel ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories This week’s ‘ThreatsDay’ bulletin highlights a diverse range of security threats, including AI-powered hacking campaigns, ransomware attacks targeting Russia, and vulnerabilities in various software systems. Notably, a C… The Hacker News · Jul 30, 2026 High CVE-2026-33017CVE-2026-21858CVE-2025-68613RUCCHransomwaresupply chainphishing