https://www.techzine.eu/news/security/134224/supply-chain-attack-via-nx-rages-on-github/
Aug 29, 2025 - The Nx build system is a popular toolkit for managing large software projects. It can currently cause security issues.
supply chain attacktechzine globalvianxrages
https://safedep.io/npm-supply-chain-attack-targeting-maintainers/
npm supply chain attacks continue. This time targeting @ctrl/tinycolor and multiple other packages with credential stealer malware. In this blog, we will...
supply chain attacknpmexposesprivaterepositories
https://dev.to/r9n/como-funciona-supply-chain-attack-ptbr-31i0
Feb 19, 2026 - Access the english version here: Click Here Olá pessoal. Hoje quero trazer um pouquinho a mais de... Tagged with node, javascript, cybersecurity, ai.
supply chain attackcomo funcionadev community
https://arstechnica.com/security/2025/05/hundreds-of-e-commerce-sites-hacked-in-supply-chain-attack/
May 5, 2025 - Attack that started in April and remains ongoing runs malicious code on visitors' devices.
hundredscommercesiteshackedsupply
https://www.databreachtoday.co.uk/salesforce-details-supply-chain-attack-targeting-gainsight-a-30108
The attack that targeted customer data management tool Gainsight resulted in the theft of information from approximately 300 Salesforce-using firms, the...
supply chain attacksalesforcedetailstargeting
https://www.huntress.com/blog/a-recap-of-events-and-lessons-learned-during-the-kaseya-vsa-supply-chain-attack
The Huntress team recaps what happened during the Kaseya VSA supply chain attack—and what we can learn from it.
supply chain attacklessons learnedvsahuntress
https://www.aikido.dev/blog/shai-hulud-strikes-again-hitting-zapier-ensdomains
The threat actor behind “Shai Hulud 2.0” launched a new malware campaign compromising the supply chain of Zapier, ENS Domains and more — exposing secrets,...
supply chain attackshaistrikesmalware
https://codenotary.com/blog/detecting-the-massive-npm-supply-chain-attack
Learn how to detect the September 2025 NPM supply chain attack that compromised debug, chalk. Includes a bash script to scan your repositories for malicious...
supply chain attackdetectingmassivenpm
https://www.bleepingcomputer.com/news/security/cloudflare-hit-by-data-breach-in-salesloft-drift-supply-chain-attack/
Cloudflare is the latest company impacted in a recent string of Salesloft Drift breaches, part of a supply-chain attack disclosed last week.
data breachsupply chaincloudflarehitsalesloft
https://cycode.com/blog/npm-debug-chalk-supply-chain-attack-the-complete-guide/
Sep 10, 2025 - Learn about the npm debug / chalk Supply-Chain Attack and how it affects popular packages and your projects.
supply chain attackcomplete guidenpmdebugchalk
https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack
Nov 24, 2025 - Shai-Hulud is back, spreading an npm malware worm through thousands of GitHub repos. Learn the impact, attacker methods, and how to defend your supply chain.
supply chain attackreposexposed
https://www.paloaltonetworks.com/blog/security-operations/the-3cx-supply-chain-attack-when-trusted-software-turns-malicious/
Jan 15, 2026 - Cortex XDR's AI stopped the 3CX supply chain attack days before the security industry knew it existed. See how behavioral detection caught what signatures...
supply chain attacktrustedsoftwareturnsmalicious
https://www.csoonline.com/article/3506897/github-actions-typosquatting-a-high-impact-supply-chain-attack-in-waiting.html
Apr 21, 2025 - Developers who mistype names and owners of GitHub Actions expose their repositories and accounts to malicious code execution, with significant software supply...
supply chain attackgithub actionshigh impacttyposquatting
https://www.csoonline.com/article/4115417/malicious-npm-packages-target-n8n-automation-platform-in-a-supply-chain-attack.html
Jan 12, 2026 - Researchers discovered malicious npm packages posing as n8n integrations, exfiltrating OAuth tokens and API keys from enterprise workflows.
npm packagesautomation platformmalicioustarget
https://safedep.io/shai-hulud-second-coming-supply-chain-attack/
Critical npm supply chain attack compromises zapier-sdk, @asyncapi, posthog, and @postman packages with self-replicating malware. Technical analysis reveals...
supply chain attacktechnical analysisshainpm
https://www.ethnews.com/trust-wallet-supply-chain-attack-drains-hundreds-of-crypto-wallets-across-evm-chains/
Jan 2, 2026 - Hundreds of crypto wallets were drained across multiple blockchains following a supply chain attack on Trust Wallet’s Chrome...
supply chain attacktrust walletcrypto walletsdrainshundreds
https://www.endorlabs.com/learn/n8mare-on-auth-street-supply-chain-attack-targets-n8n-ecosystem
How attackers weaponized n8n's community nodes to steal credentials through legitimate workflow execution
supply chain attackauthstreettargetsecosystem
https://www.aikido.dev/blog/npm-backdoor-lets-hackers-hijack-gambling-outcomes
A targeted npm supply chain attack installs an Express backdoor, enables remote SQL/file access, and rewrites gambling balances while keeping logs consistent.
supply chain attacknpmgamebackendrig
https://www.reversinglabs.com/blog/shai-hulud-worm-npm
RL researchers detected the first self-replicating worm that compromised npm packages with cloud token-stealing malware. Here's what you need to know.
supply chain attackshainpmneed
https://sveltesociety.dev/video/this-week-in-svelte-ep-116-changelog-e18e-dev-npm-supply-chain-attack-5ebe7957bd3681de
Oct 17, 2025 - Recent updates in the Svelte ecosystem, including a significant supply chain attack.
weeksvelteepchangelogdev
https://jfrog.com/blog/shai-hulud-npm-supply-chain-attack-new-compromised-packages-detected/
Dec 2, 2025 - Learn about the ongoing Shai Hulud npm supply chain attack, including all currently known compromised packages
supply chain attackshainpmnewcompromised
https://www.bleepingcomputer.com/news/security/pypi-invalidates-tokens-stolen-in-ghostaction-supply-chain-attack/
The Python Software Foundation team has invalidated all PyPI tokens stolen in the GhostAction supply chain attack in early September, confirming that the...
supply chain attackpypitokensstolen
https://hackread.com/shai-hulud-npm-worm-supply-chain-attack/
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
shainpmwormimpactsrepos
https://blog.oversecured.com/Introducing-MavenGate-a-supply-chain-attack-method-for-Java-and-Android-applications/
More recently, the cybersecurity community has seen numerous studies of supply chain attacks on Web apps.
supply chain attackintroducingmethodjava
https://bybowu.com/article/shaihulud-20-npm-supply-chain-attack-playbook
Dec 18, 2025 - Second wave of Shai‑Hulud hit npm on Nov 24. Use this step‑by‑step playbook to triage, rotate tokens, and move to Trusted Publishing now.
supply chain attacknpmplaybook
https://info.legitsecurity.com/top-3-riskiest-software-supply-chain-attack-patterns
This top 3 list of riskiest software supply chain attack patterns was created by identifying the most commonly overlapping software supply chain attack...
software supply chaintopattackpatterns
https://news.opensuse.org/2024/03/29/xz-backdoor/
openSUSE maintainers received notification of a supply chain attack against the “xz” compression tool and “liblzma5” library. Background Andres Freund...
supply chain attackopensuseaddressesxzcompression
https://www.csoonline.com/article/4028412/supply-chain-attack-compromises-npm-packages-to-spread-backdoor-malware.html
Jul 24, 2025 - Phishing attacks on package maintainer accounts led to infected JavaScript type testing utilities.
supply chain attacknpm packagescompromisesspreadbackdoor
https://www.legitsecurity.com/blog/shai-hulud-npm-attack-what-you-need-to-know
Get details on the Shai-Hulud npm, a major worm. Discover the number of compromised npm packages, the dangers, and how to plan a more secure supply chain.
supply chainnpmattackdetails
https://securityscorecard.com/what-is-a-supply-chain-attack/
Jul 1, 2025 - Learn how a supply chain attack works, why it's so dangerous, and what security measures can help protect your organization from hidden threats.
supply chain attacksecurityscorecard
https://unit42.paloaltonetworks.com/npm-supply-chain-attack/
Self-replicating worm “Shai-Hulud” has compromised hundreds of software packages in a supply chain attack targeting the npm ecosystem. We discuss scope and...
quotshaiwormcompromisesnpm
https://winbuzzer.com/2025/09/03/cloudflare-breach-exposes-customer-support-data-in-major-salesloft-supply-chain-attack-xcxwbn/
Sep 3, 2025 - Cloudflare confirms it was a victim of a major supply-chain attack via Salesloft, exposing customer support data and potential credentials from its Salesforce...
customer supportcloudflarebreachexposesdata
https://www.wired.com/story/inside-the-unnerving-supply-chain-attack-that-corrupted-ccleaner/
Apr 17, 2018 - CCleaner owner Avast is sharing more details on the malware attackers used to infect legitimate software updates with malware.
supply chain attackinsideccleanerwired
https://www.legitsecurity.com/blog/the-ultralytics-supply-chain-attack-how-it-happened-how-to-prevent
Get details on this recent supply chain attack and how to avoid falling victim to similar attacks.
supply chain attackultralyticshappened
https://www.wiz.io/blog/s1ngularity-supply-chain-attack
Aug 27, 2025 - Detect and mitigate a critical supply chain compromise affecting the Nx NPM Package. Organizations should act urgently.
supply chain attackleakssecretsgithubeverything
https://www.aikido.dev/blog/neoshadow-npm-supply-chain-attack-javascript-msbuild-blockchain
A deep technical analysis of the NeoShadow npm supply-chain attack, detailing how JavaScript, MSBuild, and blockchain techniques were combined to compromise...
supply chain attacknpmjavascriptblockchain
https://www.infoworld.com/article/4117662/possible-software-supply-chain-attack-through-aws-codebuild-service-blunted.html
Jan 15, 2026 - Researchers at Wiz, who discovered the hole, said it could have led to compromised AWS GitHub repositories.
software supply chainpossibleattackawsservice
https://www.csoonline.com/article/4117692/possible-software-supply-chain-attack-through-aws-codebuild-service-blunted-2.html
Jan 15, 2026 - Researchers at Wiz, who discovered the hole, said it could have led to compromised AWS GitHub repositories.
software supply chainpossibleattackawsservice
https://www.csoonline.com/article/4026380/prettier-eslint-npm-packages-hijacked-in-a-sophisticated-supply-chain-attack.html
Jul 22, 2025 - DLL-based malware targets Windows users after a phishing campaign tricked the maintainer into leaking a token.
npm packagessupply chainprettiereslinthijacked