#supply chain attack
28 stories taggedsupply chain attack.

Fake npm Calendar Tools Hid an AI-Powered Linux Backdoor
Researchers found 14 booby-trapped packages on the popular open-source library npm, each quietly installing a remote-control tool called RedC2 4.0 on Linux machines.

Rust developers hit by supply-chain attack on arrayref crate
Attackers hijacked a maintainer account and slipped credential-stealing malware into three popular Rust libraries during a 1.5-hour window on August 20.

Most of the 2,500 organisations hit in the LiteLLM attack were actually victims of a different breach entirely
A closer look at the data shows the Trivy scanner compromise, not the LiteLLM package, caused almost all the damage, and stolen credentials are already on sale.

Hackers hijacked BdThemes WordPress plugins to quietly create secret admin accounts
A poisoned promotional feed pushed malicious code to admin dashboards, spawning hidden accounts on sites running Element Pack and other BdThemes plugins.

AI-Generated Junk Is Clogging Apple's Bug Bounty, Ports Got Hit, and Wall Street Had a Bad Week Online
Three quieter stories from the past week: why Apple's security researchers are drowning in AI noise, how North Carolina ports came under digital attack, and a phishing email that opened a door into Wall Street.

Criminals Poisoned a Python Package Downloaded 95 Million Times a Month. AI Developers Were the Target.
On 24 March 2026, attackers slipped malicious code into LiteLLM, a software tool used by AI developers worldwide. Three hours online was enough to reach tens of thousands of companies.

The hacking crew behind a big supply-chain attack has been busy since 2020
New research links TeamPCP, the group behind a recent software supply-chain campaign, to years of quiet break-ins on exposed servers.

77 fake developer tools on Open VSX quietly mapped coders' machines for a week
The counterfeit extensions copied real names from AMD, Azure, Salesforce and others, then phoned home to a domain registered days earlier.

Fake npm Packages Pose as Alibaba Developer Tools, Drop Remote-Control Malware
Researchers found 18 booby-trapped packages on the npm registry aimed at Chinese-speaking developers, using a classic name-squatting trick to smuggle in a cross-platform remote access trojan.

Arch Linux freezes package adoptions after wave of malware sneaks into user repository
A stealer that harvests browser logins, crypto wallets and SSH keys has spread through more than 200 community-maintained Arch packages, forcing the project to hit pause.

Adform ad platform hijacked to swap crypto wallet addresses on visitor clipboards
A tampered script served through the Danish ad-tech firm's network quietly replaced Bitcoin and Ethereum addresses with attacker-controlled ones, redirecting payments from anyone who copied a wallet on an affected site.

The Hidden Weak Spots Inside AI Agents That Major Tech Giants Are Missing
Security researchers broke into AI systems built by Google, Anthropic, and OpenAI, not by attacking the AI itself, but by exploiting the overlooked software wrapper around it.

ShinyHunters claims Ernst & Young breach, points to supply-chain attack
The extortion crew says stolen credentials from a third-party supplier gave them access to EY's Jira, GitHub and Azure. The accounting giant has not confirmed the group's role.

Fake AI Tools on GitHub Are Hiding Malware, Researchers Find 7,600 Booby-Trapped Repos
A campaign called FakeGit is dressing up malicious code as AI helpers and developer tools to trick programmers into installing SmartLoader.

Two Popular Coding Tools Poisoned With Malware in Back-to-Back Supply Chain Attacks
Criminals hijacked developer credentials to slip malicious code into widely used JavaScript packages, putting any computer that installed them at serious risk.