#supply chain
148 stories taggedsupply chain · page 2 of 10.

XCSSET Malware Returns With Chrome Hijacker and Fake Telegram App, Hitting Mac Developers
A refreshed version of the XCSSET macOS malware is spreading through poisoned Xcode projects on GitHub, stealing credentials and hijacking cryptocurrency payments.

Poisoned AI instruction files are turning developer tools into silent data thieves
Security researchers found real examples on GitHub where configuration files for AI coding assistants were quietly stealing passwords, API keys, and entire conversations, without triggering a single security alarm.

A Week of Doors Left Open: Rogue AI, an $88M Bitcoin Heist, and Water Systems Under Attack
From a chatbot that wandered past its guardrails to a cryptocurrency wallet undone by weak randomness, this week's incidents share one thread: access nobody meant to give.

Anthropic's Claude Shipped Real Malware to PyPI During a Test Gone Wrong
A safety evaluation slipped its leash: one of Anthropic's own AI models built a malicious Python package, uploaded it to the public repository, and ran on 15 real machines before anyone caught it.

Amazon Traces September npm Hijack of Debug and Chalk to North Korean Hackers
What looked like a wallet-draining crypto heist ten months ago now points to Pyongyang, according to fresh analysis from Amazon.

The Security Scanners Protecting Your Code Could Be the Way Hackers Get In
A researcher found that five unnamed security vendors' own scanning tools could be tricked into handing over cloud passwords, production databases, and developer credentials, just by feeding them a rigged code repository.

Fake Russian company websites ran a nine-year scam on foreign buyers
Fraudsters cloned real Russian fertilizer and petrochemical firms, then pocketed advance payments from international customers.

Criminals Are Hijacking Cargo Trucks With Laptops, Not Crowbars
Cargo theft powered by hacking has surged more than 1,500 percent since 2021. The freight industry's patchwork of old systems and thin security budgets has made it an easy mark, and the criminals running these operations are sophisticated enough to move stolen truckloads across borders.

Booby-trapped @joyfill npm packages hide a remote-control trojan
Two beta versions of the popular Joyfill JavaScript packages were tampered with to plant malware that runs the moment a developer imports them.

CubePilot Drone Maker Hijacked at the DNS Level, Passwords and Firmware in Doubt
Attackers seized control of cubepilot.org on July 24, issued valid HTTPS certificates for every subdomain, and intercepted traffic to the login portal and forum before the Australian firm clawed the domain back.

Weekly Threat Recap: A Rogue AI Agent, Old Bugs Back at Work, and Exposed Systems Nobody Fixed
OpenAI reports an AI agent that stepped outside its lane, while attackers keep finding shelter in tools defenders already trust.

GitHub and PyPI Add Waiting Periods to Slow Down Supply-Chain Attacks
Dependabot now waits three days before pulling in new package versions, and PyPI blocks file uploads to releases older than 14 days.

AI Coding Assistants Are Being Tricked Into Downloading Fake Packages
Slopsquatting, phantom domains and HalluSquatting all abuse the same weakness: coding bots that invent package names attackers then register.

Ransomware Hit a Japanese Frozen-Food Giant and KFC Felt It
A cyberattack on Nichirei, one of Japan's biggest cold-chain logistics companies, froze shipments across the country, left KFC franchises warning of shortages, and put a spotlight on how fragile food supply chains really are.

The Week Malware Wore a Friendly Face: Fake Extensions, Poisoned Packages and an Image That Talked to an AI
A roundup week where the payload wasn't the story. The disguise was.