#supply chain
152 stories taggedsupply chain · page 8 of 11.

Over 400 AUR Packages Backdoored With Rust-Based Credential Stealer
Attackers rewrote build scripts in Arch's community repo to drop a secret-harvesting binary — with an eBPF rootkit waiting if it gets root.

LangGraph Patches Three Bugs, Including an SQLi-to-RCE Chain in Self-Hosted Agents
The framework underpinning a wave of multi-agent AI deployments shipped fixes for a flaw chain that let attackers pivot from SQL injection to code execution on self-hosted nodes.

The Cybercrime Economy Is Looking a Lot Like SaaS
A leaked worm kit, a $5K/month browser-cloning RAT, and AI agents coughing up credentials — the criminal stack is industrialising.

The Week Identity Attacks Started Looking Like SaaS
Worm kits in public repos, a subscription RAT that clones live browser sessions, and AI agents that hand over credentials when asked nicely.

npm 12 Pulls the Plug on Install Scripts by Default
GitHub is finally turning off the lifecycle hook that's been quietly powering half a decade of supply chain attacks.

protobuf.js Ships Six Bugs That Turn Schemas Into RCE Triggers
A single malicious descriptor is enough. Node.js services parsing untrusted Protobuf are the obvious blast radius.

Microsoft Pulls GitHub Repos After 73 Open-Source Projects Get Stealer-Spiked
The 'Miasma' incident looks less like a novel supply-chain zero-day and more like classic account takeover hitting a soft target: the org's own open-source footprint.

Hades Hits PyPI: 37 Poisoned Wheels Auto-Exec via .pth Trick
A fresh splinter of the Miasma supply-chain campaign abuses Python's site-packages path hook to fire on import — and goes hunting for Bun credentials.

Six Flaws in protobuf.js Turn Serialized Schemas Into Execution Vectors
The JavaScript Protocol Buffers library — pulled 50 million times a week — ships patches for a cluster of CVEs that let attackers use schema metadata to run arbitrary code inside Node.js processes.

Weekly Recap: Old Tricks, New Victims — Poisoned Packages, a Chatbot Bypass, and a GitHub Worm
A week of loud incidents masked quieter intrusions. The common thread: failures that should have been caught at code review.

Schema as Weapon: Six Flaws in protobuf.js Open a Path to Remote Code Execution
Cyera researchers found that protobuf.js — pulled into apps 50 million times a week — will, under exploitable conditions, turn schema metadata into running code.

How Ukraine Turned a Nation-State Cyberwar Into a Masterclass in Operational Resilience
Former foreign minister Dmytro Kuleba details how pre-planned contingencies — not ad-hoc crisis management — kept Ukrainian government and business functions alive under sustained Russian attack.

Microsoft Bakes a Two-Hour Quarantine Into VS Code Extension Auto-Updates
The delay is a soft tripwire against marketplace supply chain attacks — buying defenders a window to flag malicious updates before they propagate.

One-Click VS Code Flaw Exposed GitHub OAuth Tokens to Theft
A researcher-disclosed bug in Microsoft's browser-based VS Code variant let a single crafted link siphon tokens with read/write access to private repos.

Miasma Self-Replicating Worm Reaches Microsoft GitHub Orgs, 73 Repos Affected
The campaign — tracked publicly as Miasma — propagated into Azure, Azure-Samples, Microsoft, and MicrosoftDocs before GitHub pulled access.