
CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
CrowdSec reports an attack that led to the copying of 170 of its private GitHub repositories, including credentials and investor information.
Stories tagged “Supply Chain Attack.”
22 stories

CrowdSec reports an attack that led to the copying of 170 of its private GitHub repositories, including credentials and investor information.

Australian authorities arrested two men, aged 21 and 23, linked to the TeamPCP hacking group, accused of widespread supply-chain attacks that compromised over a thousand organizations globally and stole half a million credentials.

A compromised maintainer account published malicious versions of three Rust crates, which added a typosquatted dependency that downloaded and executed a remote payload during compilation. The affected releases were arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.…

Hackers compromised the maintainer account behind the widely used Rust crate arrayref to introduce malware that executed on developers' systems during compilation. The attack started at 01:17 UTC on August 20, when a GitHub account impersonating prominent Rust developer D…

A massive supply-chain attack has compromised over 1,300 packages on the Node Package Manager (npm) registry, including popular ones like Keyv and Cacheable. The attack, named 'ChainDrop', has been linked to a self-propagating malware that steals sensitive information and…

Hackers modified a JavaScript file served by Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses. Adform detected the incident on July 27, 2026, removed the malicious code, notified affected clients, and reported it to authorities.

Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors’ clipboards with ones controlled by an attacker.

Cybersecurity researchers have discovered a NuGet typosquat that's designed to rig live game results on Digitain. The package, named 'NewtonSoftt.Json.Net', masquerades as the Newtonsoft.Json library and is a trojanized fork.

Five malicious versions of AsyncAPI packages were published to the Node Package Manager (npm) in a supply-chain attack that delivered a remote access trojan with info-stealing capabilities. The threat actor exploited a misconfigured GitHub Actions workflow and pushed troj…

Hackers published a malicious version of the Jscrambler npm package, which included information-stealing malware. The package was downloaded 1,479 times before being deprecated and replaced with a safe version.

Hackers compromised the Injective Labs SDK project's GitHub repository and used it to publish a malicious package on the Node Package Manager (npm) that stole cryptocurrency wallet private keys and mnemonic seed phrases.
The Call Is Coming From Inside Your Pipeline: The Anatomy of a Codecov Attack
Codecov, a popular code analysis tool, fell victim to a supply chain attack.

Polymarket, a cryptocurrency-based prediction market, says it will fully reimburse customers who lost an estimated $3 million after hackers injected malicious script into the platform's frontend.

Miasma malware targets npm packages and GitHub Actions in a supply chain attack, compromising developer credentials and spreading across package registries. The attack affects multiple packages, including LeoPlatform and RStreams, and uses various tactics to steal secrets…

LastPass announced a data breach after hackers accessed customer data from its Salesforce environment. The breach occurred due to a supply chain attack on Klue, a third-party market intelligence platform.

Malicious npm packages have been discovered that pose as PostCSS tools to deliver a Windows-based remote access trojan. The packages were published by an npm user named 'abdrizak' and have been downloaded over 1,000 times.

Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack, affecting Pro plugin builds distributed through the vendor's Easy Digital Downloads infrastructure. The compromised plugins incorporate a loader that fetches a payload from a remote se…

Microsoft attributes Mastra AI supply chain attack to North Korean hacking group Sapphire Sleet. The attack compromised over 140 npm packages.

Multiple ShapedPlugin plugins were compromised in a supply chain attack that infected paying customers via official update system. Security incident affected three paid plugins.

CISA warns of a maximum-severity security flaw in Joomla JCE, allowing PHP code execution. The vulnerability is being actively exploited.

Supply-chain attacks often have early warning signs in dark web forums and marketplaces, appearing as leaked access to GitHub, private repositories, or vendor data, which can expose critical credentials and internal system information before a public incident.
OceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack
ESET says OceanLotus used a FireAnt Metakit supply chain attack and a separate intrusion to push SPECTRALVIPER onto Vietnamese targets.