Tag

#supply chain

152 stories taggedsupply chain · page 7 of 11.

Threat Intelligence

Three npm Packages Squat PostCSS Names to Drop a Windows RAT

Typosquatted utilities pulled roughly a thousand combined downloads before researchers flagged them. The payload targets Windows developer machines, which is exactly where the credentials live.

2 min read
Breaches

Klue Confirms OAuth Token Theft as 'Icarus' Crew Stakes Public Claim

The market intelligence vendor's disclosure adds another name to the lengthening list of Salesforce-adjacent SaaS breaches tied to stolen OAuth credentials.

3 min read
Cloud Security

Salesforce Cuts Klue Battlecards Tie-In After OAuth Token Compromise

The CRM giant pulled the competitive-intelligence app's integration on June 11 following a security incident that exposed connected customer data.

2 min read
Vulnerabilities

Beats Studio Buds Pick Up Patch for Bluetooth Pairing Flaw Rated 8.8

An Airoha SDK authorization bug let attackers within range pair without consent. Apple has shipped a firmware fix.

2 min read
Threat Intelligence

The Popa Botnet: When Your $40 Streaming Box Moonlights as a Residential Proxy

Researchers tie a four-year-old Android TV box botnet to NetNut, the residential proxy arm of NASDAQ-listed Alarum Technologies. The company disputes the framing.

3 min read
Threat Intelligence

Browser Add-Ons, AI Chat Links and In-Memory macOS Attacks: A Week the Internet Worked As Designed

Shady extensions, weaponised Claude conversations, fileless macOS intrusions and cloud agents turned into shells dominated the criminal feeds this week.

2 min read
Policy & Regulation

Mastra npm Namespace Hit: 145 Packages Tampered After Contributor Account Hijack

Researchers tracking the 'easy-day-js' supply chain incident say a single compromised maintainer account was sufficient to push malicious versions across the @mastra/* registry footprint.

2 min read
AI Security

Fifteen Rogue JetBrains Plugins Posed as DeepSeek Assistants to Siphon AI Keys

A coordinated campaign on the JetBrains Marketplace dressed up credential stealers as LLM-powered coding helpers. The payload? Your provider keys.

3 min read
AI Security

Someone Wallpapered the @mastra npm Namespace With Malicious Builds

A hijacked maintainer account pushed 144 booby-trapped packages across the Mastra AI framework before anyone noticed. The attacker called it 'easy-day-js.' It was.

2 min read
Cloud Security

'Pickle in the Middle': Vertex AI SDK Bug Let Outsiders Hijack Model Uploads

Unit 42 researchers describe a bucket-squatting flaw in Google's Python SDK that handed code execution inside Vertex AI's serving stack to attackers with no project access.

3 min read
Vulnerabilities

Twenty-Five Orgs Are Quietly Triaging Open-Source Vulns Before You Hear About Them

A coalition called Athena is building shared infrastructure to find, fix, and harden OSS projects in the window between discovery and public disclosure.

2 min read
Vulnerabilities

Weekly Recap: Chrome Zero-Day, UniFi RCE, macOS Stealers, and a VPN Auth Bypass

Another seven days of rented phishing kits, AI-themed lures, and forgotten software paying out as initial access.

3 min read
Threat Intelligence

Trusted Plugin Scripts Weaponized in Admin-Aware WordPress Supply-Chain Hit

Tampered JavaScript served from PushEngage, OptinMonster and TrustPulse fingerprinted logged-in admins before silently provisioning rogue accounts and a stealth plugin.

3 min read
Threat Intelligence

152 Chrome 'Wallpaper' Extensions Quietly Push Adware to 105K Browsers

A 38-account publisher cluster on the Chrome Web Store funnels new-tab traffic through three backends — and it looks a lot less like art and a lot more like an ad-fraud pipeline.

2 min read
Threat Intelligence

AUR Supply-Chain Hit: 400+ Arch Packages Backdoored With Rust Stealer, Optional eBPF Rootkit

Build scripts in hijacked Arch User Repository packages dropped a credential harvester — and an eBPF rootkit when root was available.

2 min read
© 2026 Threat Vectr