#supply-chain-attack — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #supply-chain-attack, aggregated by home.social.
-
Oracle Exploited: Attackers Turn SQL Injection into Windows SYSTEM Access
Attackers have successfully exploited a SQL injection vulnerability to gain unprecedented access to Oracle databases, converting it into a Windows SYSTEM-level access with alarming ease. This rare and sophisticated technique has allowed hackers to deploy a custom toolkit, dubbed khunt, that turns database-stored Java…
#SqlInjection #Oracle #Java #WindowsPrivilegeEscalation #SupplyChainAttack
-
Oracle Exploited: Attackers Turn SQL Injection into Windows SYSTEM Access
Attackers have successfully exploited a SQL injection vulnerability to gain unprecedented access to Oracle databases, converting it into a Windows SYSTEM-level access with alarming ease. This rare and sophisticated technique has allowed hackers to deploy a custom toolkit, dubbed khunt, that turns database-stored Java…
#SqlInjection #Oracle #Java #WindowsPrivilegeEscalation #SupplyChainAttack
-
A #supplychainattack on the #npm registry compromised over 1,300 packages, including popular ones like #Keyv and #Cacheable. The attack, which started with the compromise of Keyv’s #GitHub account, deployed a self-propagating malware named #ChainDrop. This #malware steals sensitive information, including developer and cloud credentials, and spreads to other packages. https://www.bleepingcomputer.com/news/security/massive-chaindrop-npm-supply-chain-attack-infects-hundreds-of-packages/?eicker.news #tech #news #ainews
-
A #supplychainattack on the #npm registry compromised over 1,300 packages, including popular ones like #Keyv and #Cacheable. The attack, which started with the compromise of Keyv’s #GitHub account, deployed a self-propagating malware named #ChainDrop. This #malware steals sensitive information, including developer and cloud credentials, and spreads to other packages. https://www.bleepingcomputer.com/news/security/massive-chaindrop-npm-supply-chain-attack-infects-hundreds-of-packages/?eicker.news #tech #news #ainews
-
Keyv and friends compromised in active Shai-Hulud supply chain attack
https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack
Comments: https://news.ycombinator.com/item?id=49166874
#HackerNews #Keyv #Shai-Hulud #supplychainattack #cybersecurity #npm
-
Keyv and friends compromised in active Shai-Hulud supply chain attack
https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack
Comments: https://news.ycombinator.com/item?id=49166874
#HackerNews #Keyv #Shai-Hulud #supplychainattack #cybersecurity #npm
-
@hacksilon PS. I like to add more hashtags to make it easier for people to find your post about malicious adform package.
#supplychain #supplychainsecurity #supplychainattack #npm #npmsecurity #ioc
-
@hacksilon PS. I like to add more hashtags to make it easier for people to find your post about malicious adform package.
#supplychain #supplychainsecurity #supplychainattack #npm #npmsecurity #ioc
-
#security / reducing the blast radius of #SupplyChainAttack question on #Ubuntu
I need to use my personal laptop for some development work. How do I reduce the blast radius of a supply chain attack on my personal laptop?
Would having 2 separate Ubuntu installed on my laptop one for dev and other for personal use be a meaningful defense?
Would building and running code in a virtualized environment (VM, Docker, etc) help or is it trivial for an attacker to escape the virtual environment?
If just on one OS, I can definitely have 2 different users (for personal use vs dev work). But is that meaningful if I have sudo access for both personal and dev accounts? Wouldn't a malicious program on the dev user account just be able to access my personal use home directory?
Open to anything that doesn't fall in the above categories.
-
#security / reducing the blast radius of #SupplyChainAttack question on #Ubuntu
I need to use my personal laptop for some development work. How do I reduce the blast radius of a supply chain attack on my personal laptop?
Would having 2 separate Ubuntu installed on my laptop one for dev and other for personal use be a meaningful defense?
Would building and running code in a virtualized environment (VM, Docker, etc) help or is it trivial for an attacker to escape the virtual environment?
If just on one OS, I can definitely have 2 different users (for personal use vs dev work). But is that meaningful if I have sudo access for both personal and dev accounts? Wouldn't a malicious program on the dev user account just be able to access my personal use home directory?
Open to anything that doesn't fall in the above categories.
-
Learn how to use the Arch User Repository (AUR) safely. Discover the lessons from the June 2026 AUR malware attack and protect your Arch Linux system.
Full details here: https://ostechnix.com/use-the-aur-safely-arch-linux/
#ArchUserRepository #AUR #ArchLinux #Security #Malware #SupplyChainAttack #AtomicArch #Linux
-
Learn how to use the Arch User Repository (AUR) safely. Discover the lessons from the June 2026 AUR malware attack and protect your Arch Linux system.
Full details here: https://ostechnix.com/use-the-aur-safely-arch-linux/
#ArchUserRepository #AUR #ArchLinux #Security #Malware #SupplyChainAttack #AtomicArch #Linux
-
Jscrambler’s npm Package Got Backdoored. The Malware Ran Before Your App Ever Started.
Jscrambler npm 8.14.0 shipped a Rust infostealer via preinstall hook, targeting cloud keys, wallets, and AI tool configs. Full technical breakdown and IOCshttps://thecybersecguru.com/news/jscrambler-npm-supply-chain-attack-2026/
-
Jscrambler’s npm Package Got Backdoored. The Malware Ran Before Your App Ever Started.
Jscrambler npm 8.14.0 shipped a Rust infostealer via preinstall hook, targeting cloud keys, wallets, and AI tool configs. Full technical breakdown and IOCshttps://thecybersecguru.com/news/jscrambler-npm-supply-chain-attack-2026/
-
Basta un npm install: la 8.14.0 di jscrambler distribuiva un infostealer Rust nelle pipeline di sviluppo
La versione 8.14.0 del popolare pacchetto npm jscrambler è stata compromessa con un preinstall hook che eseguiva silenziosamente un infostealer Rust multipiattaforma, mirato a credenziali cloud, wallet crypto e chiavi API di strumenti AI come Claude Desktop e Cursor. -
Basta un npm install: la 8.14.0 di jscrambler distribuiva un infostealer Rust nelle pipeline di sviluppo
La versione 8.14.0 del popolare pacchetto npm jscrambler è stata compromessa con un preinstall hook che eseguiva silenziosamente un infostealer Rust multipiattaforma, mirato a credenziali cloud, wallet crypto e chiavi API di strumenti AI come Claude Desktop e Cursor. -
I've blogged. Cool down your dependencies: www.eke.li/security/2026/06/19/dependency-cooldowns.html
#dev #dependencyManagement #supplychainattack -
I've blogged. Cool down your dependencies: www.eke.li/security/2026/06/19/dependency-cooldowns.html
#dev #dependencyManagement #supplychainattack -
RE: https://fosstodon.org/@archlinux/116738652549604531
#Archlinux Supply chain incident shows the thing that always ignored by common people:
Expecting you are not the target, because people rarely used it.
Which points to: Attackers will do things where it is the place you are least expect.
-
📣🚨 Over 20 Linux packages were compromised in the #AtomicArch campaign, which abuses AUR ownership transfers to drop rootkit-like malware.
Read: https://hackread.com/atomic-arch-hijacks-linux-aur-packages-malware/
-
📣🚨 Over 20 Linux packages were compromised in the #AtomicArch campaign, which abuses AUR ownership transfers to drop rootkit-like malware.
Read: https://hackread.com/atomic-arch-hijacks-linux-aur-packages-malware/
-
@sodiboo @ifin @threatintel Made a consolidated AUR malware checker for the atomic-lockfile supply-chain attack now on GitHub.
Merges detection scripts from the gist[1] and Kidev, BrianCArnold, commonsourcecs, Kacper-Kondracki, quantenProjects, Andre Herbst, ioctl.fail, and Kusoneko into a single repo. Checks known compromised packages, scans pacman.log history, checks for systemd persistence and eBPF rootkit artifacts.
https://github.com/lenucksi/aur-malware-check
UPDATE 7/13/26: Friendly contributors added a 'download official arch hedgedoc list' and the new new bun package and I added some more convenience features.
[1] https://gist.github.com/Kidev/59bf9f5fb53ab5eee99f19a6a2fc3992
#AUR #ArchLinux #SupplyChainAttack #Malware #InfoSec #atomiclockfile
-
@sodiboo @ifin @threatintel Made a consolidated AUR malware checker for the atomic-lockfile supply-chain attack now on GitHub.
Merges detection scripts from the gist[1] and Kidev, BrianCArnold, commonsourcecs, Kacper-Kondracki, quantenProjects, Andre Herbst, ioctl.fail, and Kusoneko into a single repo. Checks known compromised packages, scans pacman.log history, checks for systemd persistence and eBPF rootkit artifacts.
https://github.com/lenucksi/aur-malware-check
UPDATE 7/13/26: Friendly contributors added a 'download official arch hedgedoc list' and the new new bun package and I added some more convenience features.
[1] https://gist.github.com/Kidev/59bf9f5fb53ab5eee99f19a6a2fc3992
#AUR #ArchLinux #SupplyChainAttack #Malware #InfoSec #atomiclockfile
-
📰 "Hades Cluster" PyPI Worm Abuses Python Startup Hooks for Stealthy Credential Theft
🐍 New PyPI supply chain attack 'Hades Cluster' hits 19 packages. The worm uses a stealthy trick, abusing Python's .pth startup hooks for persistence and credential theft. #PyPI #SupplyChainAttack #Python #HadesCluster #InfoSec
🌐 cyber[.]netsecops[.]io
-
Miasma Worm Exposes GitHub Repositories in Supply Chain Attack
A sneaky Miasma worm has infiltrated 73 Microsoft GitHub repositories, putting countless projects at risk in a self-replicating supply chain attack. This malicious campaign is a stark reminder of the rapidly evolving threats lurking in the shadows of our digital supply chains.
-
Campagna Hades colpisce PyPI: 37 pacchetti malevoli della famiglia Shai-Hulud/Miasma rubano credenziali sviluppatori
Socket Research Team ha scoperto 37 wheel artifact malevoli su 19 pacchetti PyPI, parte della campagna Hades — ramo evolutivo di Shai-Hulud/Miasma. Il vettore è un file *-setup.pth che esegue silenziosamente uno stealer basato su Bun JavaScript runtime, colpendo credenziali di sviluppatori, pipeline CI/CD e ambienti cloud (AWS, GCP, Azure, GitHub, Kubernetes). -
Campagna Hades colpisce PyPI: 37 pacchetti malevoli della famiglia Shai-Hulud/Miasma rubano credenziali sviluppatori
Socket Research Team ha scoperto 37 wheel artifact malevoli su 19 pacchetti PyPI, parte della campagna Hades — ramo evolutivo di Shai-Hulud/Miasma. Il vettore è un file *-setup.pth che esegue silenziosamente uno stealer basato su Bun JavaScript runtime, colpendo credenziali di sviluppatori, pipeline CI/CD e ambienti cloud (AWS, GCP, Azure, GitHub, Kubernetes). -
Miasma Worm Targets Microsoft GitHub Repositories in Supply Chain Attack
GitHub has taken swift action, disabling access to 73 Microsoft repositories across four organizations after a sneaky supply chain attack by the Miasma Worm compromised code on the platform. The disruption was triggered when the malware targeted Microsoft's GitHub repositories, prompting site-wide warnings and restricted access.
-
Miasma Worm Weaponizes AI Coding Agents: Inside the Microsoft Azure and GitHub Supply Chain Attack Campaign
The Miasma worm targets AI coding agents via GitHub. Learn how the campaign compromised Azure durabletask & caused 73 repos to be disabledhttps://thecybersecguru.com/news/miasma-worm-targets-ai-coding-agents-github-microsoft/
-
Polyfill Compromise Targets Major Websites with Rogue Login Prompts
Major websites, including Toshiba and Muji, have been compromised by a rogue login prompt scam through polyfill.io, tricking visitors into entering sensitive information. If you encountered the fake sign-in screen, be sure to cancel and change your password to protect your account.
#PolyfillIoCompromise #RogueLoginPrompts #SupplyChainAttack #EmergingThreats #WebSecurity
-
Hola Browser Compromised to Deliver Cryptominer in Supply Chain Attack
Hola's CEO, Avi Raz Cohen, assured users that the company has taken swift action to prevent future breaches, rebuilding its distribution pipeline and implementing robust security measures. The move comes after a supply chain attack compromised the Hola Browser, secretly delivering a cryptominer to unsuspecting users.
#SupplyChainAttack #Cryptominer #HolaBrowser #MalwareOperations #EmergingThreats
-
📰 "Miasma" Worm Spreads Through npm via "Phantom Gyp" Technique, Stealing Dev Secrets
🚨 A self-spreading worm named 'Miasma' is hitting the npm registry! It uses a novel 'Phantom Gyp' technique to bypass security and steal developer secrets for AWS, GCP, GitHub & more. Check your dependencies now! 🐛 #SupplyChainAttack #npm #Miasma
🌐 cyber[.]netsecops[.]io
-
Miasma Supply Chain Attack Targets Red Hat npm Packages
A new supply-chain campaign, codenamed Miasma, has compromised multiple Red Hat npm packages to steal sensitive credentials and deliver a self-propagating worm, putting developer machines at risk. This sneaky attack uses clever tactics like install-time execution and encrypted exfiltration to harvest secrets and spread its reach.
#SupplyChainAttack #Npm #RedHat #CredentialHarvesting #CicdTargeting
-
Donating to @libreoffice.
Very important #opensource project, especially now that things are moving in the #digitalsovereignty #SupplyChainattack #enshittification #fuckmicrosoft #FuckGoogle areas.
-
Donating to @libreoffice.
Very important #opensource project, especially now that things are moving in the #digitalsovereignty #SupplyChainattack #enshittification #fuckmicrosoft #FuckGoogle areas.
-
📰 GlassWorm Malware Infrastructure Dismantled in Coordinated Takedown
✅ Takedown! CrowdStrike, Google & Shadowserver disrupt the "GlassWorm" malware C2 infrastructure. 👏 The campaign targeted developers via malicious VS Code extensions & npm packages to steal credentials. #SupplyChainAttack #CyberSecurity #Takedown
🌐 cyber[.]netsecops[.]io
-
📰 New npm Typosquatting Campaign Pushes Malware to Steal AWS and CI/CD Secrets
Microsoft uncovers a typosquatting campaign on npm by actor 'vpmdhaj'. 14 malicious packages use `preinstall` hooks to steal AWS credentials, Vault tokens, and other CI/CD secrets from developers. ⚠️ #SupplyChainAttack #npm #InfoSec
🌐 cyber[.]netsecops[.]io
-
Malicious NuGet Package Exfiltrates Sicoob Banking Credentials
A malicious NuGet package, masquerading as a C# SDK for a major Brazilian financial system, was designed to steal sensitive banking credentials, including client IDs, PFX passwords, and certificate bytes, from unsuspecting developers. This rogue package, downloaded nearly 500 times, put automation and security at risk.
#MaliciousNugetPackage #SupplyChainAttack #CredentialTheft #EmergingThreats #Brazil
-
Personal computing safety goals because of supply chain attacks and possible future issues: create new user account for new projects, clone and test repos in that account only.
Is it hard? No. Could I automate it? maybe. Would it be nice to have built into say conda? Absolutely.
#cybersecurity #programming #supplyChainAttack #Linux #sysadmin -
📰 Packagist Supply Chain Attack Uses Clever Evasion to Infect PHP Projects with Linux Malware
🚨 PHP supply chain attack hits Packagist! 8+ packages compromised to drop Linux malware. Attackers hid malicious code in `package.json` to evade PHP security scanners. #SupplyChainAttack #PHP #Packagist #CyberSecurity
🌐 cyber[.]netsecops[.]io
-
🚨 A compromise affecting the community-maintained Laravel Lang project introduced remote code execution backdoors across multiple packages, including:
- Laravel-Lang/lang
- Laravel-Lang/http-statuses
- Laravel-Lang/actions
- Laravel-Lang/attributesAll tags were rewritten pointing to malicious commits
https://github.com/Laravel-Lang/lang/issues/8295
https://github.com/Laravel-Lang/common/issues/257
https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack
https://socket.dev/blog/laravel-lang-compromise
#PHP #Laravel #SupplyChainAttack #RemoteCodeExecution #RCE #Packagist
-
asking for at least $50,000 for the stolen data.
-
#OpenSource used to mean trusting skilled developers to build and maintain good #software so others did not need to learn every language, tool, or best practice themselves.
Now, #SupplyChainAttack and #AISlop have made many projects harder to trust.
Too much software is rushed, poorly understood, or built for hype instead of quality.
#Developers now spend more time checking code, #dependencies, and #maintainers instead of simply building software.
#AI was supposed to reduce cognitive load😒