https://thehackernews.com/2022/01/hackers-target-real-estate-websites.html
Hackers Target Real Estate Websites with Skimmer in Latest Supply Chain Attack
A recent supply chain attack targeted over 100 real estate websites with a web skimmer malware, leveraging a cloud video hosting service.
real estate websitessupply chain attackhackerstargetskimmer
https://soc.cyber.wa.gov.au/advisories/20240626004-JavaScript-Polyfill-Supply-Chain-Attack/
JavaScript Polyfill Supply Chain Attack - 20240626004 - WA Cyber Security Unit (DGOV Technical)
supply chain attackcyber securityjavascriptpolyfillwa
https://dev.to/maricode/trivy-vulnerability-scanner-compromised-in-supply-chain-attack-mitigation-steps-and-user-guidance-h54
Trivy Vulnerability Scanner Compromised in Supply Chain Attack: Mitigation Steps and User Guidance...
The Breach: Understanding the Trivy Supply Chain Attack The compromise of Trivy, a... Tagged with cybersecurity, supplychain, opensource, vulnerability.
supply chain attackvulnerability scanneruser guidancetrivycompromised
https://blog.netmanageit.com/supply-chain-attack-at-cpuid-pushes-malware-with-cpu-z-hwmonitor/
Supply chain attack at CPUID pushes malware with CPU-Z/HWMonitor
Apr 10, 2026 - Hackers gained access to an API for the CPUID project and changed the download links on the official website to serve malicious executables for the popular...
supply chain attackcpu zcpuidpushesmalware
https://www.cybermaterial.com/p/ai-weaponized-nx-supply-chain-attack
AI Weaponized Nx Supply Chain Attack - CyberMaterial
A new supply chain attack, dubbed s1ngularity, targeted the popular JavaScript build system Nx, affecting thousands of developers and leading to the theft of...
supply chain attackweaponizednxcybermaterial
https://techspective.net/tag/supply-chain-attack/
supply chain attack Archives | TechSpective
supply chain attackarchivestechspective
https://www.kaspersky.com/blog/daemon-tools-supply-chain-attack/55691/
Supply chain attack via DAEMON Tools | Kaspersky official blog
Kaspersky experts have detected a supply chain attack using the popular DAEMON Tools software.
supply chain attackdaemon toolsofficial blogviakaspersky
https://www.trendmicro.com/ru_ru/research/26/d/vercel-breach-oauth-supply-chain.html
The Vercel Breach: OAuth Supply Chain Attack Exposes the Hidden Risk in Platform Environment...
Apr 20, 2026 - An OAuth supply chain compromise at Vercel exposed how trusted third party apps and platform environment variables can bypass traditional defenses and amplify...
supply chain attackvercelbreachoauthexposes
https://thecyberwire.com/newsletters/research-briefing/3/5
Supply chain attack compromises Android emulator. Tracking criminal infrastructure-as-a-service....
LogoKit makes phishing easy. Lebanese Cedar conducting cyberespionage.
supply chain attackandroid emulatortrackingcriminalinfrastructure
https://www.techmonitor.ai/technology/cybersecurity/supply-chain-attack
North Korea's Lazarus APT targets IT vendor in supply chain attack
Apr 26, 2022 - Lazarus, the APT backed by North Korea, targeted an IT asset monitoring company in one of its first supply chain attack attempts.
supply chain attacknorth korealazarusapttargets
https://www.endorlabs.com/learn/blast-radius-of-the-tj-actions-changed-files-supply-chain-attack
Blast Radius of the tj-actions/changed-files Supply Chain Attack | Blog | Endor Labs
Analysis of the tj-actions/changed-files GitHub Actions compromise, assessing the impact and damage from the attack.
supply chain attackendor labsblastradiustj
https://thedailytechfeed.com/checkmarx-github-repositories-breached-in-major-software-supply-chain-attack-by-teampcp/
Checkmarx GitHub Repositories Breached in Major Software Supply Chain Attack by TeamPCP - The Daily...
Apr 28, 2026 - Checkmarx GitHub Repositories Breached in Major Software Supply Chain Attack by TeamPCP The Daily Tech Feed -
software supply chaingithub repositoriesthe dailycheckmarxmajor
https://threatintel.cc/2025/11/25/shaihulud-supply-chain-attack.html
Threat Intel - Shai-Hulud 2.0 Supply Chain Attack
supply chain attackthreat intelshai hulud
https://www.sonarsource.com/blog/php-supply-chain-attack-on-composer
PHP Supply Chain Attack on Composer | Sonar
We recently discovered a vulnerability in Composer, the main package manager for PHP, and were able to use it to take over the central repository,...
supply chain attackphpcomposersonar
https://aviatrix.ai/blog/litellm-supply-chain-attack/
LiteLLM Supply Chain Attack: What Happened, Why It Spread, and How to Stop It
The LiteLLM supply chain attack hit 36% of cloud environments in hours. Learn what happened, how credentials were stolen, and how to contain the blast radius.
supply chain attackhow to stopwhat happenedlitellmspread
https://www.nlcyber.com/all/news/bitwarden-npm-package-hit-in-supply-chain-attack
Bitwarden NPM Package Hit in Supply Chain Attack
Tied to a fresh Checkmarx supply chain attack claimed by TeamPCP, the incident references the Shai-Hulud worm. The post Bitwarden NPM Package Hit in Supply Chai
supply chain attacknpm packagebitwardenhit
https://www.kaspersky.co.in/blog/advertising-agency-mistakes/14513/
Common small business mistakes: The supply chain attack | Kaspersky official blog
Case study: An analysis of insufficient safety practices at a small advertising agency.
supply chain attacksmall businessofficial blogcommonmistakes
https://techbytes.app/posts/glassworm-supply-chain-attack-vs-code-extensions-2026/
[Security] GlassWorm: The Supply-Chain Attack Targeting 2026 Developer Workflows | Tech Bytes
Technical analysis of the GlassWorm attack: How 72 malicious VS Code extensions on Open VSX are hijacking developer machines via dependency poisoning.
supply chain attacktech bytessecurityglasswormtargeting
https://www.kodemsecurity.com/resources/the-shai-hulud-worm-returns-new-npm-supply-chain-attack-compromises-sap-packages
Shai-Hulud Worm Returns: SAP npm Supply Chain Attack
The Shai-Hulud worm targets SAP npm packages via preinstall scripts. See affected packages, IOCs, and detection guidance for this supply chain attack.
supply chain attackshai huludwormreturnssap
https://unit42.paloaltonetworks.com/solarstorm-supply-chain-attack-timeline/?pdf=download&lg=en&_wpnonce=c49489dfaf
SolarStorm Timeline: Details of the Software Supply-Chain Attack
Jun 6, 2024 - The SolarStorm timeline summarized here is based on the information available to us and our direct experience defending against this threat.
software supply chaintimelinedetailsattack
https://online.maryville.edu/blog/supply-chain-attack/
Supply Chain Attack: Preventing Ransomware Attacks on the Supply Chain | Maryville Online
Oct 25, 2023 - Supply chain attacks threaten to disrupt worldwide commerce via ransomware and other cybercrimes. Discover supply chain attack examples and prevention tips.
supply chain attackransomware attackson themaryvilleonline
https://cloud.google.com/blog/topics/threat-intelligence/north-korea-threat-actor-targets-axios-npm-package
North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack |...
A North Korea-nexus threat actor targeted the popular axios NPM package in a massive supply chain attack.
supply chain attacknorth koreathreat actornpm packagenexus
https://www.techtarget.com/searchsecurity/news/252483808/Supply-chain-attack-hits-26-open-source-projects-on-GitHub
Supply chain attack hits 26 open source projects on GitHub | TechTarget
A massive supply chain attack, which used malware called Octopus Scanner, was discovered on GitHub. After investigating, GitHub's security team uncovered 26...
supply chain attackopen source projectson githubhits
https://www.dataworldbank.net/2026/05/05/widely-used-daemon-tools-disk-app-backdoored-in-monthlong-supply-chain-attack/
Widely used Daemon Tools disk app backdoored in monthlong supply-chain attack - Technology data bank
May 5, 2026 - Daemon Tools, a widely used app for mounting disk images, has been backdoored in a monthlong compromise that has pushed malicious updates from the servers of...
supply chain attackdaemon toolstechnology datawidelyused
https://www.threatshub.org/blog/possible-supply-chain-attack-targeting-pakistani-government-delivers-shadowpad/
Possible Supply-Chain Attack Targeting Pakistani Government Delivers Shadowpad 2026 | ThreatsHub...
supply chain attackpossibletargetingpakistanigovernment
https://securityarsenal.com/blog/pypi-supply-chain-attack-zichatbot-malware-delivered-via-zulip-apis-on-linux-and-windows
PyPI Supply Chain Attack: ZiChatBot Malware Delivered via Zulip APIs on Linux & Windows | Security...
May 7, 2026 - Active PyPI supply chain attack delivers ZiChatBot malware via Zulip APIs. Immediate detection and containment required for Python environments.
supply chain attackwindows securitypypimalwaredelivered
https://www.eset.com/int/about/newsroom/press-releases/research/iran-aligned-agrius-group-deploys-new-wiper-through-supply-chain-attack-in-diamond-industry-eset-research-discovers/
Iran-aligned Agrius group deploys new wiper through supply-chain attack in diamond industry, ESET...
Your source for cyber security news, reviews, expert opinions and upcoming events.
supply chain attackdiamond industryiranalignedagrius
https://api-security.blog/2025/05/03/malicious-go-modules-deliver-disk-wiping-linux-malware-in-advanced-supply-chain-attack/
Malicious Go Modules Deliver Disk-Wiping Linux Malware in Advanced Supply Chain Attack - API...
May 3, 2025 - Cybersecurity researchers have discovered three malicious Go modules that include obfuscated code to fetch next-stage payloads that can irrevocably overwrite a...
supply chain attackgo modulesmaliciousdeliverdisk
https://vpncentral.com/pytorch-lightning-and-intercom-packages-hit-by-credential-stealing-supply-chain-attack/
PyTorch Lightning and Intercom packages hit by credential-stealing supply chain attack
May 3, 2026 - A new supply chain attack has hit the Python, npm, and PHP package ecosystems, with malicious versions of Lightning and Intercom packages used to steal...
supply chain attackpytorchlightningintercompackages
https://www.ox.security/blog/vercel-context-ai-supply-chain-attack-breachforums/
Vercel Breached via Context AI Supply Chain Attack
May 10, 2026 - A compromised Context AI employee triggered a supply chain attack on Vercel, exposing internal environment variables and a database access key now being sold...
ai supply chainvercelviacontextattack
https://www.threatlocker.com/blog/axios-supply-chain-attack-how-a-compromised-npm-package-delivered-rat-malware
Axios supply chain attack: How a compromised npm package delivered RAT malware
A malicious Axios npm release compromised over 10,000 systems in hours. Learn how the attack worked, the IoCs, and how to prevent supply chain attacks.
supply chain attacknpm packageaxioscompromiseddelivered
https://www.itsecuritynews.info/daemon-tools-software-hacked-to-deliver-malware-in-a-supply-chain-attack/
DAEMON Tools Software Hacked to Deliver Malware in a Supply Chain Attack - IT Security News
May 5, 2026 - In a sophisticated supply chain attack discovered in early May 2026, the popular disk image mounting software DAEMON Tools has been compromised to deliver...
supply chain attackit security newsdaemon toolssoftwarehacked
https://cyber.netsecops.io/articles/scattered-lapsus-hunters-claim-supply-chain-breach-via-gainsight-salesforce-integration/
Massive Supply Chain Attack Hits 200+ Companies via Salesforce App; Hacker Group Claims Breach -...
Dec 6, 2025 - A major supply chain attack by the 'Scattered Lapsus$ Hunters' group has compromised over 200 companies by exploiting OAuth tokens from the Gainsight app...
supply chain attacksalesforce appgroup claimsmassivehits
https://news.ssbcrack.com/supply-chain-attack-compromises-dozens-of-wordpress-plugins-from-essential-plugin-suite-exposing-thousands-of-websites-to-backdoor-malware/
Supply Chain Attack Compromises Dozens of WordPress Plugins from Essential Plugin Suite, Exposing...
Apr 15, 2026 - A sophisticated supply chain attack has compromised approximately 30 popular WordPress plugins developed under the Essential Plugin brand, formerly known as
supply chain attackwordpress pluginsdozensessentialsuite
https://thecybertrove.com/npm-supply-chain-attack-hugging-face-malware/
npm Supply Chain Attack Exploits Hugging Face Malware
Apr 23, 2026 - npm supply chain attack abuses Hugging Face for malware delivery and data theft, exposing cross-platform implants and exfiltration risks.
supply chain attackhugging facenpmexploitsmalware
https://www.guardianmssp.com/2023/09/02/vmconnect-supply-chain-attack-persists-33/
VMConnect Supply Chain Attack Persists | GuardianMSSP
supply chain attack
https://www.exploitone.com/tag/supply-chain-attack/
supply chain attack Archives - Cyber Security News | Exploit One | Hacking News
supply chain attackcyber security newsarchivesexploitone
https://researchportal.rma.ac.be/nl/projects/software-supply-chain-attack-and-defence/
SOftware suppLy chain Attack and defenCE - Koninklijke Militaire School
software supply chainattackdefencekoninklijkemilitaire
https://www.malwarebytes.com/blog/news/2026/03/axios-supply-chain-attack-chops-away-at-npm-trust?ref=christophermoravec.com
Axios supply chain attack chops away at npm trust | Malwarebytes
Mar 31, 2026 - Developers using the axios package from npm may have downloaded a malicous version that drops a Remote Access Trojan
supply chain attackaxioschopsawaynpm
https://www.justoglobal.com/news/p/hundreds-of-ecommerce-sites-hacked-in-supplychain-sPQed0Rd
Massive E-Commerce Supply Chain Attack | Justo Global
Discover how a major supply-chain attack compromised numerous online stores, impacting Magento users. Stay informed to protect your e-commerce platform.
supply chain attacke commercemassivejustoglobal
https://infinitsec.net/posts/let-ai-fix-your-ci-is-a-supply-chain-attack-waiting-to-happen-heres-how-to-do
Tools: Let AI fix your CI" is a supply chain attack waiting to happen. Here's how to do it safely -...
Apr 19, 2026 - ## What it does ## The three hard constraints ### 1. Scope fence ### 2. Prompt injection defense ### 3.
supply chain attackdo ittoolsletfix
https://www.hendryadrian.com/supply-chain-attack-hits-npm-package-with-45000-weekly-downloads/
Supply chain attack hits npm package with 45,000 weekly downloads
Oct 13, 2025 - A malicious supply chain attack compromised the npm package 'rand-user-agent', injecting obfuscated code that activates a remote access trojan (RAT) on users'...
supply chain attacknpm packagehitsweeklydownloads
https://therecord.media/supply-chain-attack-hits-widely-used-ai-package
Supply chain attack hits widely-used AI package, risks impacting thousands of companies | The...
The incident highlights growing concerns over the security of the open-source software supply chain, where widely-used tools maintained by small teams can...
supply chain attackthousands of companieshitswidelyused
https://www.thestack.technology/npm-software-supply-chain-attack-advice/
Lessons from npm's largest software supply chain attack
Sep 10, 2025 - A npm maintainer's account was hacked on Monday leading to packages with over 2 billion weekly downloads to be compromised.
software supply chainlessonsnpmlargestattack
https://blackkite.com/blog/focus-friday-tprm-insights-on-polyfill-supply-chain-attack-and-moveit-cisco-nx-os-openssh-apache-tomcat-progress-whatsup-gold-and-microsoft-mshtml-vulnerabilitiesfocus-friday-tprm-insights-on-polyfill
TPRM INSIGHTS ON POLYFILL SUPPLY CHAIN ATTACK AND MOVEit, CISCO NX-OS, OPENSSH, APACHE TOMCAT,...
Welcome to this week's Focus Friday blog, where we delve into critical vulnerabilities impacting today's digital landscape from a Third-Party Risk Management...
supply chain attackapache tomcattprminsightspolyfill
https://holder.io/news/ledger-cto-warns-users-npm-supply-chain-attack/
Ledger CTO Alerts Users to NPM Supply Chain Attack Affecting 1 Billion Downloads
Sep 8, 2025 - Charles Guillemet, CTO of Ledger, reported a large-scale supply chain attack linked to a compromised Node Package Manager (NPM) account. Key points include:...
supply chain attackledgerctoalertsusers
https://www.cybersecuritydive.com/news/supply-chain-attack-3cx-desktop-thousands/646432/
Supply chain attack against 3CX communications app could impact thousands | Cybersecurity Dive
Researchers warn a state-linked actor has launched malicious activity against a voice application widely used by major corporate customers.
supply chain attackcybersecurity divecommunicationsappcould
https://candid.technology/npm-repository-supply-chain-attack-malicious-packages/
Supply chain attack targets NPM repository with malicious packages
Major NPM supply chain attack targets hundreds of popular code libraries, including Puppeteer, threatening developer systems.
supply chain attackmalicious packagestargetsnpmrepository
https://bitnewsbot.com/bitwarden-cli-compromised-by-checkmarx-supply-chain/
Bitwarden CLI Compromised By Checkmarx Supply Chain Attack
Apr 23, 2026 - The Bitwarden CLI became the latest victim in an ongoing supply chain campaign, with a malicious version published on April 22, 2026, according to new
bitwarden cli compromisedsupply chain attackcheckmarx
https://securityaid.co.uk/2026/04/04/european-commission-confirms-data-breach-linked-to-trivy-supply-chain-attack/
European Commission Confirms Data Breach Linked to Trivy Supply Chain Attack - Security Aid
Apr 4, 2026 - Stay updated with the latest security news and updates on Security Aid. Read our informative article about European Commission Confirms Data Breach Linked to...
supply chain attackeuropean commissiondata breachlinkedtrivy
https://gateway.on24.com/wcc/eh/1220486/lp/3067080/from_sunspot_to_sunburst_preventing_the_next_software_supply_chain_attack/
From SunSpot to SunBurst: Preventing the Next Software Supply Chain Attack
software supply chainthe nextsunspotsunburstattack
https://www.esentire.com/security-advisories/3cx-supply-chain-attack
3CX Supply Chain Attack | eSentire
THE THREAT eSentire is aware of an ongoing supply chain attack impacting the voice and video conferencing application 3CXDesktopApp. As of March 22nd, 2023, a...
supply chain attack
https://www.orsys.fr/orsys-lemag/en/glossary_tag/attack-on-the-supply-chain/
Supply Chain Attack Archives - ORSYS Le mag
supply chain attackle magarchives
https://socprime.com/pt/tag/supply-chain-attack/
Supply Chain Attack | SOC Prime
Browse Supply Chain Attack content on SOC Prime. Find 2 articles tagged with Supply Chain Attack.
supply chain attacksoc prime
https://themenonlab.blog/litellm-one-interface-100-llms-supply-chain-attack/
Redirecting to: /blog/litellm-one-interface-100-llms-supply-chain-attack
supply chain attackto blogredirectinglitellmone
https://stinner-it.com/jumpcloud-supply-chain-attack-47/
JumpCloud Supply-Chain Attack | Stinner IT Solutions
supply chain attackit solutionsjumpcloud
https://www.fox-it.com/be-en/case-study-incident-response-to-a-nation-state-supply-chain-attack/
Case Study: Incident Response to a Nation-State Supply Chain Attack | Fox IT
supply chain attackcase studyincident responsenation statefox
https://www.mend.io/blog/npm-supply-chain-attack-infiltrates-popular-packages/
NPM Supply Chain Attack Hits Popular Packages with Crypto Drainer
Sep 11, 2025 - A sophisticated npm supply chain attack compromised popular packages, injecting malware that hijacks Web3 wallets and drains cryptocurrency.
supply chain attackpopular packageswith cryptonpmhits
https://iplogger.org/blog/attack-on-axios-software-developer-tool-threatens-widespread-compromises/
Axios Supply Chain Attack: A Critical Threat to 100 Million Weekly Downloads
Supply chain attack on Axios threatens widespread compromises. Learn about the threat, impact, and advanced mitigation strategies.
supply chain attackaxioscriticalthreatmillion
https://hb.int2inf.com/en/s/item/Px9gHHNfbzmK9PeiEZzPjb-daemon-tools-supply-chain-attack-malicious-updates
Widely used Daemon Tools disk app backdoored in monthlong supply-chain attack | Hasty Briefs
May 5, 2026 - Daemon Tools was compromised for about a month, with malicious updates signed by the developer's certificate and distributed via its website., Infected...
supply chain attackdaemon toolswidelyuseddisk
https://app.govly.com/public/signals/95246
Disc Soft Addresses Daemon Tools Supply Chain Attack | Govly
In April 2026, Disc Soft, the developer of Daemon Tools Lite, responded to a widespread supply chain cyberattack that embedded backdoors into its software...
supply chain attackdaemon toolsdiscsoftaddresses
https://securitybrief.asia/story/anatomy-of-a-supply-chain-attack-how-to-accelerate-incident-response-and-threat-hunting
Anatomy of a supply chain attack: how to accelerate incident response and threat hunting
Supply chain attacks show no sign of slowing down. But the right combination of platforms can help organisations get ahead of the threat.
supply chain attackhow toincident responsethreat huntinganatomy
https://www.darktrace.com/es/solutions/supply-chain-attack
Supply Chain Attack Protection | Detect, Contain, & Secure
Detecting supply chain attacks, from vendor email compromise to open-source software, is a challenge. Learn how AI-based tools stop supply chain attacks.
supply chain attackprotectiondetectcontainsecure
https://securityaffairs.com/156029/hacking/ledger-supply-chain-attack.html
Supply chain attack on crypto hw wallet Ledger led to the theft of $600K
Dec 18, 2023 - A supply chain attack against Crypto hardware wallet maker Ledger resulted in the theft of $600,000 in virtual assets.
supply chain attackto thecryptohwwallet
https://cybersecurity-see.com/bitwarden-cli-password-manager-compromised-in-supply-chain-attack/
Bitwarden CLI Password Manager Compromised in Supply Chain Attack | CyberSecurity SEE
supply chain attackpassword managerbitwardenclicompromised
https://www.paubox.com/blog/axios-supply-chain-attack-raises-alarm
Axios supply chain attack raises alarm
Google Threat Intelligence Group said a software supply chain attack briefly compromised the widely used JavaScript HTTP library axios on March 31, 2026.
supply chain attackaxiosalarm
https://www.wiz.io/blog/s1ngularity-supply-chain-attack?ref=20papercups.net
s1ngularity: supply chain attack leaks secrets on GitHub: everything you need to know | Wiz Blog
Aug 27, 2025 - Detect and mitigate a critical supply chain compromise affecting the Nx NPM Package. Organizations should act urgently.
supply chain attackeverything you needon githubleakssecrets
https://fluidattacks.com/blog/glassworm-vs-code-extensions-supply-chain-attack
GlassWorm supply chain attack | Fluid Attacks
The sophisticated GlassWorm malware affected VS Code extensions, using invisible Unicode to steal credentials and install a full RAT on developers' machines.
supply chain attackglasswormfluidattacks
https://vercel.com/changelog/s1ngularity-supply-chain-attack-in-nx-packages
s1ngularity: supply chain attack in Nx packages - Vercel
A critical vulnerability was published in Nx and some of its supporting libraries. Vercel builds are safe from this vulnerability by default.
supply chain attacknxpackagesvercel
https://kb.filewave.com/books/security-information/page/supply-chain-attack-threat-management
Supply-Chain Attack Th... | FileWave KB
QUESTION How well is FileWave's product protected against Supply-Chain Attacks? What efforts does F...
supply chain attackthkb
https://cyberscoop.com/radio/data-scientist-rumman-chowdhury/
Rumman Chowdhury on AI red-teaming; a Sisense supply chain attack | CyberScoop
Aug 6, 2024 - Rumman Chowdhury, Data scientist
ai red teamingsupply chain attackrumman chowdhurysisensecyberscoop