Tag

#supply chain attack

28 stories taggedsupply chain attack.

A computer monitor displaying a compromised website homepage with subtle visual corruptions and overlay glitches, surrounded by scattered cables and keyboard in
Breaches

Hacker Backdoored a WordPress Plugin's Own Website, Hitting 1,500 Sites

The maker of Admin Menu Editor Pro says an attacker took over his site and shipped two poisoned updates that installed a hidden admin account on customer sites.

3 min read
A computer workstation displaying cascading code and network diagrams in dim blue light, with forensic investigation equipment and documentation scattered acros
Threat Intelligence

Australian police arrest two alleged members of TeamPCP supply-chain crew

The pair, from Western Australia, are linked to a hacking collective that poisoned open-source software used by thousands of companies, and to the extortion crew Fulcrumsec.

4 min read
A developer's screen showing a code repository with file integrity verification failing, malicious code highlighted in red among legitimate modules, Cloudflare
Cloud Security

Attackers Hijacked Coder's Cloudflare Setup to Push Poisoned Terraform Modules

For 14 hours on August 31, some developers pulling from Coder's official registry got credential-stealing code instead of the real thing.

4 min read
Internet routing infrastructure visualization showing network packets and DNS paths, with one segment highlighting a poisoned update server delivering malicious
Threat Intelligence

Hackers hijacked internet routing to push a poisoned Virtualizor update

Softaculous says attackers rerouted its update servers for 33 hours, delivering a malicious update to a small number of hosting providers running Virtualizor.

4 min read
Police vehicles and law enforcement activity outside a technology-related facility in Western Australia, with digital security imagery on nearby screens
Threat Intelligence

Australian Police Arrest Two Alleged Members of Supply-Chain Extortion Crew TeamPCP

The Western Australia arrests target a group blamed for a year-long run of open-source software attacks, including the Shai-Hulud worm that hit thousands of companies.

4 min read
A developer's workstation with a code editor showing package dependencies and terminal windows with security warnings, with red alert indicators on the screen
Threat Intelligence

Fake npm Calendar Tools Hid an AI-Powered Linux Backdoor

Researchers found 14 booby-trapped packages on the popular open-source library npm, each quietly installing a remote-control tool called RedC2 4.0 on Linux machines.

3 min read
A developer's workspace with multiple monitors showing code repositories and package manager windows, with one screen displaying a compromised file alert overla
Vulnerabilities

Rust developers hit by supply-chain attack on arrayref crate

Attackers hijacked a maintainer account and slipped credential-stealing malware into three popular Rust libraries during a 1.5-hour window on August 20.

3 min read
Cybersecurity incident timeline chart on a large monitor showing the LiteLLM package compromise alongside the separate Trivy scanner vulnerability, with data da
Threat Intelligence

Most of the 2,500 organisations hit in the LiteLLM attack were actually victims of a different breach entirely

A closer look at the data shows the Trivy scanner compromise, not the LiteLLM package, caused almost all the damage, and stolen credentials are already on sale.

4 min read
A WordPress admin dashboard displaying installed plugins including Element Pack, a hidden admin account notification visible in a suspicious log entry, maliciou
Vulnerabilities

Hackers hijacked BdThemes WordPress plugins to quietly create secret admin accounts

A poisoned promotional feed pushed malicious code to admin dashboards, spawning hidden accounts on sites running Element Pack and other BdThemes plugins.

3 min read
A tech support inbox flooded with hundreds of automated emails and low-quality submissions piling up on a desktop, with a tired security researcher in the backg
Threat Intelligence

AI-Generated Junk Is Clogging Apple's Bug Bounty, Ports Got Hit, and Wall Street Had a Bad Week Online

Three quieter stories from the past week: why Apple's security researchers are drowning in AI noise, how North Carolina ports came under digital attack, and a phishing email that opened a door into Wall Street.

4 min read
A developer's workstation screen showing lines of code being examined under a magnifying glass, with warning symbols floating in the digital space around it, re
AI Security

Criminals Poisoned a Python Package Downloaded 95 Million Times a Month. AI Developers Were the Target.

On 24 March 2026, attackers slipped malicious code into LiteLLM, a software tool used by AI developers worldwide. Three hours online was enough to reach tens of thousands of companies.

4 min read
Multiple computer server racks photographed from an angle, with subtle indicators of unauthorized access points and backdoors visible in the infrastructure, rep
Threat Intelligence

The hacking crew behind a big supply-chain attack has been busy since 2020

New research links TeamPCP, the group behind a recent software supply-chain campaign, to years of quiet break-ins on exposed servers.

3 min read
A developer's computer monitor displaying code in an IDE, with network activity indicators and connection logs visible on the screen, suggesting background data
Threat Intelligence

77 fake developer tools on Open VSX quietly mapped coders' machines for a week

The counterfeit extensions copied real names from AMD, Azure, Salesforce and others, then phoned home to a domain registered days earlier.

4 min read
Developer workspace with code editor displaying npm package registry interface, malicious package listings highlighted, security scanning tools running in backg
Threat Intelligence

Fake npm Packages Pose as Alibaba Developer Tools, Drop Remote-Control Malware

Researchers found 18 booby-trapped packages on the npm registry aimed at Chinese-speaking developers, using a classic name-squatting trick to smuggle in a cross-platform remote access trojan.

4 min read
A developer's workstation with multiple code editor windows open, repository trees visible, red error warnings cascading across displays, chaos of digital conte
Threat Intelligence

Arch Linux freezes package adoptions after wave of malware sneaks into user repository

A stealer that harvests browser logins and crypto wallets has spread through more than 200 community-maintained Arch packages, forcing the project to hit pause.

4 min read
© 2026 Threat Vectr