#supply chain
152 stories taggedsupply chain · page 4 of 11.

China's Military Is Quietly Banning Its Own Cybersecurity Companies
Chinese armed forces are shutting some of the country's biggest cybersecurity firms out of military contracts, and the reason has nothing to do with bad software.

The 'Approval Gap' in Ad Tech: When Marketing Tags Smuggle in Unknown Code
A single approved script on your website can quietly pull in code from vendors your security team has never heard of. Here is why that matters.

Cursor on Windows Runs Rogue git.exe From Any Opened Repo, No Warning
A flaw in the AI code editor lets a booby-trapped repository execute code on a developer's machine the moment the folder is opened.

Hijacked AsyncAPI npm Packages Slipped a Botnet Loader Into Developer Machines
Four packages under the popular @asyncapi namespace were tampered with to deliver a multi-stage malware loader, in the latest reminder that the open-source supply chain is a soft target.

Popular AI Coding Tool Cursor Runs Malicious Files Automatically, Researcher Warns
A security firm reported the flaw seven months ago. Cursor has yet to patch it.

Poisoned Developer Tool Downloaded Nearly 1,500 Times Before Anyone Noticed
Criminals hijacked the publishing credentials for a widely used JavaScript security package and slipped malware into four releases over a single weekend. Developers who installed any of those versions may have handed over passwords, crypto-wallet keys, and cloud access tokens without knowing it.

Fake Student Proxies on npm Turned Browsers Into a DDoS Weapon
Researchers at JFrog say 148 malicious packages used the npm registry as free hosting for a booby-trapped proxy site, quietly enlisting students' browsers into a two-week attack campaign in May.

Chrome and Edge Yank ModHeader Extension After Hidden History Collector Found
The browser add-on had 1.6 million users. A dormant tracker sat inside its official store version, though no evidence suggests it ever ran.

Lidl Customers in Three Countries Warned After Supplier Breach Exposes Personal Data
The German discount chain says a file at an outside IT provider was raided, spilling names, phone numbers and dates of birth for online shoppers in Germany, Belgium and the Netherlands.

Attackers Hijacked Injective Labs' GitHub to Slip Wallet-Stealing Code Into npm
A tampered @injectivelabs/sdk-ts release quietly siphoned crypto wallet keys and seed phrases from developers who installed it.

Hackers Are Targeting the Companies Behind Your Hospital, Not Just the Hospital Itself
Attacks on healthcare businesses, the billing firms and IT vendors that keep hospitals running, surged 110% in a year. Experts say criminals have figured out that one breach can unlock hundreds of patients at once.

Poisoned Injective SDK on npm quietly stole crypto wallet keys for hours
A hijacked contributor account on GitHub pushed a booby-trapped version of a popular blockchain toolkit, siphoning seed phrases from any developer who ran the wrong function.

Old, Silent GitHub Accounts Are Being Used to Quietly Map Companies
Datadog Security Labs says several overlapping scraping campaigns are cataloguing corporate GitHub organisations using dormant 'ghost' accounts and stolen tokens.

Your Business Is Already a Wartime Target. Here Is What to Do About It.
Nation-states attacking private companies is not a future risk. It happened at scale in 2017 and the conditions that made it possible have only grown more complicated since.

AI Coding Assistants Can Be Tricked Into Running the Very Malware They Were Asked to Find
A proof-of-concept from the AI Now Institute shows Claude Code and OpenAI's Codex executing attacker-supplied code when asked to review it in autonomous mode.