#supply-chain-attack — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #supply-chain-attack, aggregated by home.social.
-
🦀 Atac de tip Supply Chain în ecosistemul Rust: Pachetul extrem de popular arrayref (245M+ descărcări) a fost compromis!Pe 20 august 2026, comunitatea de securitate și echipa Rust Security Response Team au intervenit de urgență pentru a elimina versiuni contaminate ale câtorva crate-uri extrem de populare. Contul de menținător al dezvoltarorului David Roundy a fost compromis, permițând atacatorilor să lanseze versiuni otrăvite de pachete în doar câteva zeci de minute. ✨ Detaliile atacului și modul de funcționare:📦 Pachetele afectate și modul de infectare:• Versiunile otrăvite publicate au fost arrayref 0.3.10, internment 0.8.7 și append-only-vec 0.1.9.• Atacatorii au injectat o dependență nouă numită proc-macro1, un pachet typosquat ce imita cunoscutul proc-macro2. ⚡ Execuție la nivel de compilare (Build-Time RCE):• Codul malițios era ascuns în fișierul build.rs al dependenței proc-macro1.
• Deoarece Cargo rulează fișierele build.rs automat în momentul compilării, simpla compilare a unui proiect care aducea indirect pachetele afectate executa malware-ul pe calculatorul dezvoltatorului, fără ca pachetul să fie apelat efectiv în cod. 🕵️ Payload și exfiltrare de date:• Scriptul descarca un binary specific sistemului de operare (Linux, macOS sau Windows).• Pachetul software funcționa ca un Infostealer, extras de date de sistem și de date de autentificare stocate în browsere bazate pe Chromium (Google Chrome, Brave, Microsoft Edge).• Analizele oferite de cercetători de securitate (cum ar fi Wiz) leagă infrastructura atacului de gruparea de hackeri nord-coreeni Sapphire Sleet. 🚨 Răspunsul rapid al echipei Rust:• Versiunile compromise au fost șterse complet de pe crates.io într-o fereastră de doar 86–107 minute de la publicare.• Contul afectat a fost securizat, iar pachetele au fost restaurate la versiunile sigure. 🔍 Ce trebuie să faci dacă lucrezi cu Rust?Verifică memoria cache locală din folderul Cargo pentru a te asigura că nu ai descărcat una dintre versiunile problematice:Bashfind ~/.cargo/registry/cache -type f \( -name 'arrayref-0.3.10.crate' -o -name 'internment-0.8.7.crate' -o -name 'append-only-vec-0.1.9.crate' -o -name 'proc-macro1-*.crate' \)
Un memento serios că atacurile de tip supply chain rămân o amenințare majoră, chiar și în ecosisteme cu accent pe siguranță precum Rust! 🚀#Rust #RustLang #SupplyChainAttack #CyberSecurity #InfoSec #Arrayref #Cargo #Linuxiac #TechNews #OpenSource -
A Rust supply chain attack poisoned arrayref and two other crates to run malware at build time. Wiz ties the infrastructure to DPRK campaigns.
#RustLang #SupplyChainAttack #arrayref #DPRK #DevSecOps #InfoSec #Cybersecurity
-
If you are developing in #Rustlang then you should check this post: https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/
-
Kaspersky: APAC cyber threats remain high, 75 million attacks blocked in six months #apac #apt #cyberattack #cybersecurity #digitallife #escan #great #kaspersky #kasperskygreat #news #notepad #supplychainattack
https://soyacincau.com/2026/08/18/kaspersky-apac-75-million-attacks-blocked-h1-2026/
-
Hey everyone! Terabytes worth of #credentials, for more than 2500 massive Fortune 500 type orgs have been exposed in a supply-chain attack on #LiteLLM.
The breach was reported Tuesday and Wednesday by security firms #CloudSEK and #HudsonRock. (Links below) CloudSEK said it found cloud keys, repository tokens, #SSH keys, #Kubernetes secrets, package publishing credentials, environment variables, and AI provider #keys.
This, in the world of #infosec, is called A Bad Thing. The fact that some of the credentials are still live, is mind boggling.
#ai #security #SupplyChainAttack #hack
https://www.cloudsek.com/blog/ai-supply-chain-breach-2500-companies-434000-cicd-pipelines
Companies exposed: https://exposure.cloudsek.com/ai-supply-chain-incident
ArsTecnica overview: https://arstechnica.com/security/2026/08/terabytes-of-credentials-leaked-in-massive-supply-chain-attack/
-
A #supplychainattack on the #opensource tool #LiteLLM exposed #terabytes of #credentials belonging to over 2,500 organisations, including Microsoft, Amazon, and Cisco. The attack, attributed to the group TeamPCP, exploited a #vulnerability in the #vulnerabilityscanner #Trivy and compromised versions of LiteLLM, KICS, and the Telnyx Python SDK. Security firms CloudSEK and Hudson Rock urge affected organisations to rotate credentials. https://arstechnica.com/security/2026/08/terabytes-of-credentials-leaked-in-massive-supply-chain-attack/?eicker.news #tech #news #ainews
-
Reward: You've received a Participation Certificate (Compromised Edition). It is non-transferable. Your credentials, however, were.
#SupplyChainAttack #Malware #npm #SoftwareSecurity #CredentialTheft #WormPropagation (3/3)
-
Lieferketten-Angriff auf #keyv: #ShaiHulud-Wurm infiziert mehr als 440 #npm-Pakete | Developer https://www.heise.de/news/Lieferketten-Angriff-auf-keyv-Shai-Hulud-Wurm-infiziert-mehr-als-440-npm-Pakete-11403078.html #SupplyChain #SupplyChainAttack #malware
-
Oracle Exploited: Attackers Turn SQL Injection into Windows SYSTEM Access
Attackers have successfully exploited a SQL injection vulnerability to gain unprecedented access to Oracle databases, converting it into a Windows SYSTEM-level access with alarming ease. This rare and sophisticated technique has allowed hackers to deploy a custom toolkit, dubbed khunt, that turns database-stored Java…
#SqlInjection #Oracle #Java #WindowsPrivilegeEscalation #SupplyChainAttack
-
A #supplychainattack on the #npm registry compromised over 1,300 packages, including popular ones like #Keyv and #Cacheable. The attack, which started with the compromise of Keyv’s #GitHub account, deployed a self-propagating malware named #ChainDrop. This #malware steals sensitive information, including developer and cloud credentials, and spreads to other packages. https://www.bleepingcomputer.com/news/security/massive-chaindrop-npm-supply-chain-attack-infects-hundreds-of-packages/?eicker.news #tech #news #ainews
-
Keyv and friends compromised in active Shai-Hulud supply chain attack
https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack
Comments: https://news.ycombinator.com/item?id=49166874
#HackerNews #Keyv #Shai-Hulud #supplychainattack #cybersecurity #npm
-
@hacksilon PS. I like to add more hashtags to make it easier for people to find your post about malicious adform package.
#supplychain #supplychainsecurity #supplychainattack #npm #npmsecurity #ioc
-
#security / reducing the blast radius of #SupplyChainAttack question on #Ubuntu
I need to use my personal laptop for some development work. How do I reduce the blast radius of a supply chain attack on my personal laptop?
Would having 2 separate Ubuntu installed on my laptop one for dev and other for personal use be a meaningful defense?
Would building and running code in a virtualized environment (VM, Docker, etc) help or is it trivial for an attacker to escape the virtual environment?
If just on one OS, I can definitely have 2 different users (for personal use vs dev work). But is that meaningful if I have sudo access for both personal and dev accounts? Wouldn't a malicious program on the dev user account just be able to access my personal use home directory?
Open to anything that doesn't fall in the above categories.
-
Learn how to use the Arch User Repository (AUR) safely. Discover the lessons from the June 2026 AUR malware attack and protect your Arch Linux system.
Full details here: https://ostechnix.com/use-the-aur-safely-arch-linux/
#ArchUserRepository #AUR #ArchLinux #Security #Malware #SupplyChainAttack #AtomicArch #Linux
-
Jscrambler’s npm Package Got Backdoored. The Malware Ran Before Your App Ever Started.
Jscrambler npm 8.14.0 shipped a Rust infostealer via preinstall hook, targeting cloud keys, wallets, and AI tool configs. Full technical breakdown and IOCshttps://thecybersecguru.com/news/jscrambler-npm-supply-chain-attack-2026/
-
Basta un npm install: la 8.14.0 di jscrambler distribuiva un infostealer Rust nelle pipeline di sviluppo
La versione 8.14.0 del popolare pacchetto npm jscrambler è stata compromessa con un preinstall hook che eseguiva silenziosamente un infostealer Rust multipiattaforma, mirato a credenziali cloud, wallet crypto e chiavi API di strumenti AI come Claude Desktop e Cursor. -
I've blogged. Cool down your dependencies: www.eke.li/security/2026/06/19/dependency-cooldowns.html
#dev #dependencyManagement #supplychainattack -
RE: https://fosstodon.org/@archlinux/116738652549604531
#Archlinux Supply chain incident shows the thing that always ignored by common people:
Expecting you are not the target, because people rarely used it.
Which points to: Attackers will do things where it is the place you are least expect.
-
📣🚨 Over 20 Linux packages were compromised in the #AtomicArch campaign, which abuses AUR ownership transfers to drop rootkit-like malware.
Read: https://hackread.com/atomic-arch-hijacks-linux-aur-packages-malware/
-
@sodiboo @ifin @threatintel Made a consolidated AUR malware checker for the atomic-lockfile supply-chain attack now on GitHub.
Merges detection scripts from the gist[1] and Kidev, BrianCArnold, commonsourcecs, Kacper-Kondracki, quantenProjects, Andre Herbst, ioctl.fail, and Kusoneko into a single repo. Checks known compromised packages, scans pacman.log history, checks for systemd persistence and eBPF rootkit artifacts.
https://github.com/lenucksi/aur-malware-check
UPDATE 7/13/26: Friendly contributors added a 'download official arch hedgedoc list' and the new new bun package and I added some more convenience features.
[1] https://gist.github.com/Kidev/59bf9f5fb53ab5eee99f19a6a2fc3992
#AUR #ArchLinux #SupplyChainAttack #Malware #InfoSec #atomiclockfile
-
Campagna Hades colpisce PyPI: 37 pacchetti malevoli della famiglia Shai-Hulud/Miasma rubano credenziali sviluppatori
Socket Research Team ha scoperto 37 wheel artifact malevoli su 19 pacchetti PyPI, parte della campagna Hades — ramo evolutivo di Shai-Hulud/Miasma. Il vettore è un file *-setup.pth che esegue silenziosamente uno stealer basato su Bun JavaScript runtime, colpendo credenziali di sviluppatori, pipeline CI/CD e ambienti cloud (AWS, GCP, Azure, GitHub, Kubernetes). -
Donating to @libreoffice.
Very important #opensource project, especially now that things are moving in the #digitalsovereignty #SupplyChainattack #enshittification #fuckmicrosoft #FuckGoogle areas.