home.social

#supplychainattack — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #supplychainattack, aggregated by home.social.

  1. Personal computing safety goals because of supply chain attacks and possible future issues: create new user account for new projects, clone and test repos in that account only.
    Is it hard? No. Could I automate it? maybe. Would it be nice to have built into say conda? Absolutely.
    #cybersecurity #programming #supplyChainAttack #Linux #sysadmin

  2. Personal computing safety goals because of supply chain attacks and possible future issues: create new user account for new projects, clone and test repos in that account only.
    Is it hard? No. Could I automate it? maybe. Would it be nice to have built into say conda? Absolutely.
    #cybersecurity #programming #supplyChainAttack #Linux #sysadmin

  3. Personal computing safety goals because of supply chain attacks and possible future issues: create new user account for new projects, clone and test repos in that account only.
    Is it hard? No. Could I automate it? maybe. Would it be nice to have built into say conda? Absolutely.
    #cybersecurity #programming #supplyChainAttack #Linux #sysadmin

  4. Personal computing safety goals because of supply chain attacks and possible future issues: create new user account for new projects, clone and test repos in that account only.
    Is it hard? No. Could I automate it? maybe. Would it be nice to have built into say conda? Absolutely.
    #cybersecurity #programming #supplyChainAttack #Linux #sysadmin

  5. Personal computing safety goals because of supply chain attacks and possible future issues: create new user account for new projects, clone and test repos in that account only.
    Is it hard? No. Could I automate it? maybe. Would it be nice to have built into say conda? Absolutely.
    #cybersecurity #programming #supplyChainAttack #Linux #sysadmin

  6. 📰 Packagist Supply Chain Attack Uses Clever Evasion to Infect PHP Projects with Linux Malware

    🚨 PHP supply chain attack hits Packagist! 8+ packages compromised to drop Linux malware. Attackers hid malicious code in `package.json` to evade PHP security scanners. #SupplyChainAttack #PHP #Packagist #CyberSecurity

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/co

  7. 📰 Packagist Supply Chain Attack Uses Clever Evasion to Infect PHP Projects with Linux Malware

    🚨 PHP supply chain attack hits Packagist! 8+ packages compromised to drop Linux malware. Attackers hid malicious code in `package.json` to evade PHP security scanners. #SupplyChainAttack #PHP #Packagist #CyberSecurity

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/co

  8. 📰 Packagist Supply Chain Attack Uses Clever Evasion to Infect PHP Projects with Linux Malware

    🚨 PHP supply chain attack hits Packagist! 8+ packages compromised to drop Linux malware. Attackers hid malicious code in `package.json` to evade PHP security scanners. #SupplyChainAttack #PHP #Packagist #CyberSecurity

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/co

  9. 📰 Packagist Supply Chain Attack Uses Clever Evasion to Infect PHP Projects with Linux Malware

    🚨 PHP supply chain attack hits Packagist! 8+ packages compromised to drop Linux malware. Attackers hid malicious code in `package.json` to evade PHP security scanners. #SupplyChainAttack #PHP #Packagist #CyberSecurity

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/co

  10. 📰 Packagist Supply Chain Attack Uses Clever Evasion to Infect PHP Projects with Linux Malware

    🚨 PHP supply chain attack hits Packagist! 8+ packages compromised to drop Linux malware. Attackers hid malicious code in `package.json` to evade PHP security scanners. #SupplyChainAttack #PHP #Packagist #CyberSecurity

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/co

  11. GitHub-Hosted Malware Targets PHP Packages in Coordinated Supply Chain Attack

    Malicious code was injected into eight PHP packages on Packagist, triggering a Linux binary download from GitHub Releases via JavaScript lifecycle hooks in package.json postinstall scripts. The attack was swiftly contained, with the malicious versions removed from Packagist.

    osintsights.com/github-hosted-

    #SupplyChainAttack #Github #Php #Packagist #Javascript

  12. GitHub Actions Supply Chain Attack Exfiltrates CI/CD Credentials

    A sneaky supply chain attack on GitHub Actions has led to the theft of CI/CD credentials, with hackers using a clever trick to redirect tags to fake commits that hide malicious code. By masquerading as legitimate commits, attackers were able to execute arbitrary code and evade pull request reviews.

    osintsights.com/github-actions

    #SupplyChainAttack #GithubActions #CicdCredentials #ImposterCommits #EmergingThreats

  13. #OpenSource used to mean trusting skilled developers to build and maintain good #software so others did not need to learn every language, tool, or best practice themselves.

    Now, #SupplyChainAttack and #AISlop have made many projects harder to trust.

    Too much software is rushed, poorly understood, or built for hype instead of quality.

    #Developers now spend more time checking code, #dependencies, and #maintainers instead of simply building software.

    #AI was supposed to reduce cognitive load😒

  14. 🚨 Breaking news! 🚨 A supply chain attack on #npm shocks #developers worldwide, and in an utterly predictable twist, the only package manager where this "regularly happens" shrugs and says, "Oops, our bad." 😅 Devs are now collectively wringing their hands, wondering how they got #bamboozled by the same trick for the zillionth time. 🤦‍♂️
    kevinpatel.xyz/posts/no-way-to #supplychainattack #security #shocked #oops #HackerNews #ngated

  15. 🚨 Breaking news! 🚨 A supply chain attack on #npm shocks #developers worldwide, and in an utterly predictable twist, the only package manager where this "regularly happens" shrugs and says, "Oops, our bad." 😅 Devs are now collectively wringing their hands, wondering how they got #bamboozled by the same trick for the zillionth time. 🤦‍♂️
    kevinpatel.xyz/posts/no-way-to #supplychainattack #security #shocked #oops #HackerNews #ngated

  16. 🚨 Breaking news! 🚨 A supply chain attack on #npm shocks #developers worldwide, and in an utterly predictable twist, the only package manager where this "regularly happens" shrugs and says, "Oops, our bad." 😅 Devs are now collectively wringing their hands, wondering how they got #bamboozled by the same trick for the zillionth time. 🤦‍♂️
    kevinpatel.xyz/posts/no-way-to #supplychainattack #security #shocked #oops #HackerNews #ngated

  17. 🚨 Breaking news! 🚨 A supply chain attack on #npm shocks #developers worldwide, and in an utterly predictable twist, the only package manager where this "regularly happens" shrugs and says, "Oops, our bad." 😅 Devs are now collectively wringing their hands, wondering how they got #bamboozled by the same trick for the zillionth time. 🤦‍♂️
    kevinpatel.xyz/posts/no-way-to #supplychainattack #security #shocked #oops #HackerNews #ngated

  18. 🚨 Breaking news! 🚨 A supply chain attack on #npm shocks #developers worldwide, and in an utterly predictable twist, the only package manager where this "regularly happens" shrugs and says, "Oops, our bad." 😅 Devs are now collectively wringing their hands, wondering how they got #bamboozled by the same trick for the zillionth time. 🤦‍♂️
    kevinpatel.xyz/posts/no-way-to #supplychainattack #security #shocked #oops #HackerNews #ngated

  19. #Socket detected a #supplychainattack on 84 #TanStack #npm packages, including popular ones like tanstack/react-router, which were compromised with suspected credential-stealing malware. The attack involved a chained #GitHub Actions attack and resulted in the publication of malicious packages authenticated through the project’s #OIDC trusted-publisher binding. socket.dev/blog/tanstack-npm-p #tech #media #news

  20. #Socket detected a #supplychainattack on 84 #TanStack #npm packages, including popular ones like tanstack/react-router, which were compromised with suspected credential-stealing malware. The attack involved a chained #GitHub Actions attack and resulted in the publication of malicious packages authenticated through the project’s #OIDC trusted-publisher binding. socket.dev/blog/tanstack-npm-p #tech #media #news

  21. #Socket detected a #supplychainattack on 84 #TanStack #npm packages, including popular ones like tanstack/react-router, which were compromised with suspected credential-stealing malware. The attack involved a chained #GitHub Actions attack and resulted in the publication of malicious packages authenticated through the project’s #OIDC trusted-publisher binding. socket.dev/blog/tanstack-npm-p #tech #media #news

  22. #Socket detected a #supplychainattack on 84 #TanStack #npm packages, including popular ones like tanstack/react-router, which were compromised with suspected credential-stealing malware. The attack involved a chained #GitHub Actions attack and resulted in the publication of malicious packages authenticated through the project’s #OIDC trusted-publisher binding. socket.dev/blog/tanstack-npm-p #tech #media #news

  23. #Socket detected a #supplychainattack on 84 #TanStack #npm packages, including popular ones like tanstack/react-router, which were compromised with suspected credential-stealing malware. The attack involved a chained #GitHub Actions attack and resulted in the publication of malicious packages authenticated through the project’s #OIDC trusted-publisher binding. socket.dev/blog/tanstack-npm-p #tech #media #news

  24. Malware Targets TanStack npm Packages in Supply Chain Attack

    Malware attackers have infiltrated the TanStack npm packages, modifying 84 artifacts in a supply chain attack that could compromise major developer ecosystems. The malicious code, aimed at stealing credentials, was published across 42 packages on May 11, with some, like @tanstack/react-router, downloaded over 12 million times…

    osintsights.com/malware-target

    #SupplyChainAttack #Tanstack #Npm #MalwareOperations #CredentialstealingMalware

  25. تعرض الموقع الرسمي لـ JDownloader لاختراق أمني خطير، مما أدى إلى توزيع برمجيات خبيثة عبر روابط تثبيت ويندوز ولينكس لأكثر من يوم. استغل المهاجمون ثغرة غير مصححة لتعديل الروابط واستبدالها بملفات ضارة غير موقعة. بعد بلاغات المستخدمين وتحذيرات SmartScreen، تم إغلاق الموقع للتحقيق. لم تتأثر ملفات macOS والتحديثات عبر منصات مثل WinGet وFlatpak، وظلت آمنة. هذا الهجوم يمثل هجوم سلسلة توريد استغل سمعة JDownloader لنشر البرمجيات الخبيثة.

    #JDownloader #Malware #SupplyChainAttack

  26. Checkmarx Plugin Compromised with Infostealer in Supply-Chain Attack

    A rogue version of Checkmarx's Jenkins Application Security Testing plugin was compromised by the TeamPCP hacker group, who left a taunting message in the about section, claiming another supply-chain attack success. The group has been linked to a string of similar breaches, delivering credential-stealing malware.

    osintsights.com/checkmarx-plug

    #SupplyChainAttack #Teampcp #Jenkins #Checkmarx #Infostealer

  27. Daemon Tools Software Trojanized in Supply Chain Attack

    Malware was discovered hidden in certain Daemon Tools Lite installers, prompting developer Disc Soft to issue a clean build and confirm a supply chain attack had compromised their system. A malware-free version was released within 12 hours of notification.

    osintsights.com/daemon-tools-s

    #SupplyChainAttack #MalwareOperations #DaemonTools #EmergingThreats

  28. CW: Détails techniques 3/9

    Avantages (suite)

    - #nobuild : pas de build requis (oubliez npm et autres package.json) : le code écrit est exactement celui qui est exécuté sur le navigateur sans transformation. Les libs sont inclues dans un dossier "vendor" et ne sont pas téléchargées via un gestionnaire de dépendances (évite les #supplychainattack)