#supplychainattack

14 posts · Last used 4d

Back to Timeline
CyberWorldOps @cyberworldops@infosec.exchange · 4d ago
BdThemes, a WordPress premium tool developer, was compromised in a supply-chain attack. Attackers injected malicious JavaScript into a remote JSON feed rendered in WordPress admin panels, enabling automatic creation of rogue administrator accounts on victim sites. #SupplyChainAttack #WordPress #BdThemes #Cybersecurity https://cyberworldops.eu/en/bdthemes-compromised-wordpress-supply-chain-attack-creates-rogue
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Aug 06, 2026
XCSSET v40 malware infects macOS developers through poisoned Xcode projects on GitHub, then hides in memory. Unit 42 found 17 modules and Chrome hijacking. #XCSSET #macOS #Malware #SupplyChainAttack #CyberSecurity #Xcode http://securityonline.info/xcsset-v40-malware-macos-developers/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Aug 04, 2026
A new npm supply chain attack hijacked keyv and dozens of packages, spreading Shai-Hulud malware that steals cloud and CI/CD secrets. Rotate keys now. #npm #SupplyChainAttack #ShaiHulud #keyv #CredentialStealer #Malware #DevSecOps #CICD #CyberSecurity #InfoSec https://securityonline.info/npm-supply-chain-attack-keyv-shai-hulud/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Aug 03, 2026
A distributed npm supply chain attack dropped a cross-platform RAT on Alibaba developers. Socket found malicious npm packages hiding loader code. #npm #SupplyChainAttack #RAT #Alibaba #Malware #CyberSecurity https://securityonline.info/npm-supply-chain-attack-alibaba-rat/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Security Crawler Carl @security_crawler_carl@infosec.exchange · Aug 02, 2026
Replying to @security_crawler_carl@infosec.exchange
Cursed items do not ask permission. Reward: Your inventory is full. You have received Malware Sample (Unidentified). You cannot drop it. #CyberSecurity #AISecurityRisks #SupplyChainAttack #Phishing #Ransomware #AchievementUnlocked (3/3)
0
0
0
nullpo1nt3r @nullpo1nt3r@infosec.exchange · Jul 28, 2026
#ThreatIntel #YARA #SupplyChainAttack rule ADFORM_TRACKPOINT_CLIPPER_2026 { meta: description = "Clipboard hijacker appended to Adform trackpoint-async.js" author = "Raze Security" date = "2026-07-28" reference = "s2.adform.net/banners/scripts/st/trackpoint-async.js" tlp = "CLEAR" strings: $key = /0x4d\s*,\s*0x33\s*,\s*0x77\s*,\s*0x54\s*,\s*0x77\s*,\s*0x30/ nocase $f1 = "_hookValue" ascii $f2 = "_scanInputs" ascii $f3 = "_scanText" ascii $c2 = "84.32.102.230:7744" ascii $path = "/p?h=" ascii $btc = "bc1qmplgt0hcg62jc2guz86wn2sms7tqrsulkkrrls" ascii $eth = "0xE7983E69df17079ADb0aD7b3458488Cac0dBc573" ascii nocase $re = "[1-9A-HJ-NP-Za-km-z]{33}" ascii $clip = "navigator.clipboard.readText" ascii condition: $c2 or $btc or $eth or ($key and 1 of ($f*)) or (2 of ($f*) and $clip and $re) or ($c2 and $path) }
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 26, 2026
Discover how the SANDWORM_MODE worm targets AI toolchains, developer environments, and supply chains to exfiltrate secrets and wipe files. #SANDWORM_MODE #Cybersecurity #SupplyChainAttack #AIToolchain #MalwareAnalysis https://meterpreter.org/sandworm-mode-worm-attack/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 23, 2026
A GitHub Actions abuse campaign turned thousands of workflows into cPanel and WHM exploitation infrastructure, harvesting cloud and payment credentials. #GitHubActionsAbuse #cPanelExploitation #WHM #SupplyChainAttack #Packagist https://securityonline.info/github-actions-abuse-cpanel-whm-exploitation/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 06, 2026
North Korea-linked PolinRider expands to npm, Go modules, Packagist, and Chrome extensions with 162 malicious artifacts targeting developers. #PolinRider #SupplyChainAttack #NorthKorea #ContagiousInterview #npm https://meterpreter.org/polinrider-supply-chain-attack/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
𝕂𝚞𝚋𝚒𝚔ℙ𝚒𝚡𝚎𝚕™ @kubikpixel@chaos.social · Jul 05, 2026
This will increase a lot of uncertainty in all areas: «Artificial Intelligence — Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks: Decades-old Bash shell tricks can bypass safeguards in most open source AI coding agents, potentially turning malicious repositories into supply chain attack vectors.» 🤜 https://www.securityweek.com/decades-old-bash-tricks-expose-ai-coding-agents-to-supply-chain-attacks/ #bash #decates #hacking #ai #bypass #itsec #itsecurity #supplychain #aicoding #supplychainattack #gnu #linux #unix #aws
1
1
2
Cloud 🤖 @cloud@infosec.exchange · Jul 04, 2026
🤖 North Korean threat actors published 108 malicious packages and browser extensions across npm, Packagist, Go, and Chrome Web Store in the ongoing PolinRider campaign. Supply-chain attack targets maintainer accounts — new packages continue to appear. 🔗 https://thehackernews.com/2026/07/north-korean-hackers-publish-108.html #SupplyChainAttack #Malware #CyberSec #PolinRider
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 03, 2026
New research reveals an Android signing key leak tied to 278 real apps and over 10 billion users, plus a working Baidu Keyboard exploit. #AndroidSecurity #SigningKeyLeak #SupplyChainAttack #Baidu #KeystoreLeak https://meterpreter.org/android-signing-key-leak/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Adhidarma Hadiwinoto :verifyc: @adhisimon@mastodon.kodesumber.com · Mar 31, 2026
Replying to on gts.sangeunahna.com
@sakeudeung@gts.sangeunahna.com kayaknya gak akan banyak yang kena karena versi #axios yang kena inject terbatas. Kode-kode yang cukup lama sepertinya malah aman. Kayaknya ya, blm baca lebih detail juga. Lapar. https://github.com/axios/axios/issues/10604 https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan #nodejs #axios #vulnerabiliy #cvs #supplychainattack
1
0
0

You've seen all posts