#supply chain
152 stories taggedsupply chain · page 7 of 11.

Three npm Packages Squat PostCSS Names to Drop a Windows RAT
Typosquatted utilities pulled roughly a thousand combined downloads before researchers flagged them. The payload targets Windows developer machines, which is exactly where the credentials live.

Klue Confirms OAuth Token Theft as 'Icarus' Crew Stakes Public Claim
The market intelligence vendor's disclosure adds another name to the lengthening list of Salesforce-adjacent SaaS breaches tied to stolen OAuth credentials.

Salesforce Cuts Klue Battlecards Tie-In After OAuth Token Compromise
The CRM giant pulled the competitive-intelligence app's integration on June 11 following a security incident that exposed connected customer data.

Beats Studio Buds Pick Up Patch for Bluetooth Pairing Flaw Rated 8.8
An Airoha SDK authorization bug let attackers within range pair without consent. Apple has shipped a firmware fix.

The Popa Botnet: When Your $40 Streaming Box Moonlights as a Residential Proxy
Researchers tie a four-year-old Android TV box botnet to NetNut, the residential proxy arm of NASDAQ-listed Alarum Technologies. The company disputes the framing.

Browser Add-Ons, AI Chat Links and In-Memory macOS Attacks: A Week the Internet Worked As Designed
Shady extensions, weaponised Claude conversations, fileless macOS intrusions and cloud agents turned into shells dominated the criminal feeds this week.

Mastra npm Namespace Hit: 145 Packages Tampered After Contributor Account Hijack
Researchers tracking the 'easy-day-js' supply chain incident say a single compromised maintainer account was sufficient to push malicious versions across the @mastra/* registry footprint.

Fifteen Rogue JetBrains Plugins Posed as DeepSeek Assistants to Siphon AI Keys
A coordinated campaign on the JetBrains Marketplace dressed up credential stealers as LLM-powered coding helpers. The payload? Your provider keys.

Someone Wallpapered the @mastra npm Namespace With Malicious Builds
A hijacked maintainer account pushed 144 booby-trapped packages across the Mastra AI framework before anyone noticed. The attacker called it 'easy-day-js.' It was.

'Pickle in the Middle': Vertex AI SDK Bug Let Outsiders Hijack Model Uploads
Unit 42 researchers describe a bucket-squatting flaw in Google's Python SDK that handed code execution inside Vertex AI's serving stack to attackers with no project access.

Twenty-Five Orgs Are Quietly Triaging Open-Source Vulns Before You Hear About Them
A coalition called Athena is building shared infrastructure to find, fix, and harden OSS projects in the window between discovery and public disclosure.

Weekly Recap: Chrome Zero-Day, UniFi RCE, macOS Stealers, and a VPN Auth Bypass
Another seven days of rented phishing kits, AI-themed lures, and forgotten software paying out as initial access.

Trusted Plugin Scripts Weaponized in Admin-Aware WordPress Supply-Chain Hit
Tampered JavaScript served from PushEngage, OptinMonster and TrustPulse fingerprinted logged-in admins before silently provisioning rogue accounts and a stealth plugin.

152 Chrome 'Wallpaper' Extensions Quietly Push Adware to 105K Browsers
A 38-account publisher cluster on the Chrome Web Store funnels new-tab traffic through three backends — and it looks a lot less like art and a lot more like an ad-fraud pipeline.

AUR Supply-Chain Hit: 400+ Arch Packages Backdoored With Rust Stealer, Optional eBPF Rootkit
Build scripts in hijacked Arch User Repository packages dropped a credential harvester — and an eBPF rootkit when root was available.