#supply


Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack

Jun 26, 2026 // 14:08

Cybersecurity researchers have flagged yet another evolution of the supply chain attack linked to the Mini Shai-Hulud, Miasma, and Hades malware family that has compromised […]

LastPass confirms data breach in Klue supply chain attack

Jun 23, 2026 // 17:17

LastPass announced that hackers accessed customer data from its Salesforce environment after stealing the company’s OAuth tokens in the Klue supply chain attack earlier this […]

ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack

Jun 22, 2026 // 21:04

Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors managed to tamper with the official release channels and […]

Microsoft links Mastra AI supply chain attack to North Korean hackers

Jun 20, 2026 // 19:57

Microsoft has attributed a recent Mastra AI supply chain attack that compromised more than 140 npm packages to the North Korean hacking group Sapphire Sleet, […]

GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks

Jun 11, 2026 // 10:17

GitHub has announced what it said are “breaking changes” coming to npm version 12, one of which turns off install scripts by default to combat […]

VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks

Jun 8, 2026 // 09:10

Microsoft has announced that Visual Studio Code (VS Code) will apply a two-hour delay before extensions for the integrated development environment (IDE) are updated automatically […]

Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack

Jun 6, 2026 // 11:48

Microsoft’s GitHub repositories have become the latest to fall victim to the ongoing Miasma self-replicating supply chain attack campaign. The incident impacted 73 Microsoft repositories […]

IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks

Jun 5, 2026 // 23:42

Multiple software supply chain attacks have hit the npm ecosystem, with threat actors using both malicious and poisoned versions of over 50 legitimate packages to […]

Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm

Jun 1, 2026 // 22:14

A new Mini Shai-Hulud supply chain attack campaign, codenamed Miasma, has compromised @redhat-cloud-services packages to steal credentials and secrets from developer machines and deliver a […]

OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack

Jun 1, 2026 // 12:33

Cybersecurity researchers have disclosed details of a new malicious supply chain campaign that’s targeting developers using OpenAI Codex through a legitimate-looking remote web UI. The […]