#supply chain attack
28 stories taggedsupply chain attack · page 2 of 2.

Adform ad platform hijacked to swap crypto wallet addresses on visitor clipboards
A tampered script served through the Danish ad-tech firm's network quietly replaced Bitcoin and Ethereum addresses with attacker-controlled ones, redirecting payments from anyone who copied a wallet on an affected site.

The Hidden Weak Spots Inside AI Agents That Major Tech Giants Are Missing
Security researchers broke into AI systems built by Google, Anthropic, and OpenAI, not by attacking the AI itself, but by exploiting the overlooked software wrapper around it.

ShinyHunters claims Ernst & Young breach, points to supply-chain attack
The extortion crew says stolen credentials from a third-party supplier gave them access to EY's Jira, GitHub and Azure. The accounting giant has not confirmed the group's role.

Fake AI Tools on GitHub Are Hiding Malware, Researchers Find 7,600 Booby-Trapped Repos
A campaign called FakeGit is dressing up malicious code as AI helpers and developer tools to trick programmers into installing SmartLoader.

Two Popular Coding Tools Poisoned With Malware in Back-to-Back Supply Chain Attacks
Criminals hijacked developer credentials to slip malicious code into widely used JavaScript packages, putting any computer that installed them at serious risk.

Trojanised AsyncAPI packages slip onto npm, hitting a library downloaded 2.25 million times a week
Attackers hijacked a GitHub build pipeline on 14 July to publish five poisoned versions of AsyncAPI tools, wiring in a stealthy info-stealer that talks to its operators over Ethereum and peer-to-peer networks.

Malicious Jscrambler npm package stole developer secrets for two hours before takedown
A poisoned release of the Jscrambler npm package was downloaded almost 1,500 times, scooping up cloud keys, wallet seed phrases and browser credentials before the company pulled it.

Booby-trapped jscrambler npm release runs infostealer the moment you install it
Version 8.14.0 of a popular JavaScript protection package shipped with a hidden payload that fires during install, no code changes required from the developer.

Over 200 Fake GitHub Repositories Caught Secretly Installing Windows Malware
A criminal operation called Muck and Load built a web of 222 phoney code repositories to trick software developers into downloading password-stealing programs, spyware, and cryptominers.

Iran-Linked Hackers Hit Israeli IT Firms to Reach High-Value Targets
A group tied to Iran used a flexible, plug-in-style hacking toolkit to break into IT service providers in Israel, then moved through those companies to attack their clients.

An AI Coding Tool Built Into Millions of Developer Setups Had a Flaw That Could Hand Hackers Your Cloud Keys
A security hole in Amazon's AI coding assistant let criminals steal cloud credentials just by getting a developer to open a poisoned folder. It's patched, but the attack method is spreading.

ShapedPlugin's Update Channel Hijacked, Pro Plugins Shipped with Backdoor
Attackers slipped malicious code into licensed Pro releases by compromising the vendor's own build pipeline, a clean supply-chain hit on WordPress installs.

War Room Debrief: How a Fictional Grocery Chain Got Crushed by APT 64
A tabletop exercise at Infosecurity Europe put ransomware, AI poisoning, and deepfake CEO videos inside a simulated supermarket attack. The blue team held the line. The red team shorted the stock anyway.