#supply chain attack
28 stories taggedsupply chain attack.

Hacker Backdoored a WordPress Plugin's Own Website, Hitting 1,500 Sites
The maker of Admin Menu Editor Pro says an attacker took over his site and shipped two poisoned updates that installed a hidden admin account on customer sites.

Australian police arrest two alleged members of TeamPCP supply-chain crew
The pair, from Western Australia, are linked to a hacking collective that poisoned open-source software used by thousands of companies, and to the extortion crew Fulcrumsec.

Attackers Hijacked Coder's Cloudflare Setup to Push Poisoned Terraform Modules
For 14 hours on August 31, some developers pulling from Coder's official registry got credential-stealing code instead of the real thing.

Hackers hijacked internet routing to push a poisoned Virtualizor update
Softaculous says attackers rerouted its update servers for 33 hours, delivering a malicious update to a small number of hosting providers running Virtualizor.

Australian Police Arrest Two Alleged Members of Supply-Chain Extortion Crew TeamPCP
The Western Australia arrests target a group blamed for a year-long run of open-source software attacks, including the Shai-Hulud worm that hit thousands of companies.

Fake npm Calendar Tools Hid an AI-Powered Linux Backdoor
Researchers found 14 booby-trapped packages on the popular open-source library npm, each quietly installing a remote-control tool called RedC2 4.0 on Linux machines.

Rust developers hit by supply-chain attack on arrayref crate
Attackers hijacked a maintainer account and slipped credential-stealing malware into three popular Rust libraries during a 1.5-hour window on August 20.

Most of the 2,500 organisations hit in the LiteLLM attack were actually victims of a different breach entirely
A closer look at the data shows the Trivy scanner compromise, not the LiteLLM package, caused almost all the damage, and stolen credentials are already on sale.

Hackers hijacked BdThemes WordPress plugins to quietly create secret admin accounts
A poisoned promotional feed pushed malicious code to admin dashboards, spawning hidden accounts on sites running Element Pack and other BdThemes plugins.

AI-Generated Junk Is Clogging Apple's Bug Bounty, Ports Got Hit, and Wall Street Had a Bad Week Online
Three quieter stories from the past week: why Apple's security researchers are drowning in AI noise, how North Carolina ports came under digital attack, and a phishing email that opened a door into Wall Street.

Criminals Poisoned a Python Package Downloaded 95 Million Times a Month. AI Developers Were the Target.
On 24 March 2026, attackers slipped malicious code into LiteLLM, a software tool used by AI developers worldwide. Three hours online was enough to reach tens of thousands of companies.

The hacking crew behind a big supply-chain attack has been busy since 2020
New research links TeamPCP, the group behind a recent software supply-chain campaign, to years of quiet break-ins on exposed servers.

77 fake developer tools on Open VSX quietly mapped coders' machines for a week
The counterfeit extensions copied real names from AMD, Azure, Salesforce and others, then phoned home to a domain registered days earlier.

Fake npm Packages Pose as Alibaba Developer Tools, Drop Remote-Control Malware
Researchers found 18 booby-trapped packages on the npm registry aimed at Chinese-speaking developers, using a classic name-squatting trick to smuggle in a cross-platform remote access trojan.

Arch Linux freezes package adoptions after wave of malware sneaks into user repository
A stealer that harvests browser logins and crypto wallets has spread through more than 200 community-maintained Arch packages, forcing the project to hit pause.