PROBABLYPWNED
Home/Tag/Supply Chain

Supply Chain

66 articles tagged with "Supply Chain"

Megalodon Attack Backdoors 5,561 GitHub Repos in Six Hours
Malware4 min read

Megalodon Attack Backdoors 5,561 GitHub Repos in Six Hours

Automated Megalodon campaign pushed 5,718 malicious commits to GitHub repos on May 18, injecting CI/CD workflows that exfiltrate cloud credentials, SSH keys, and secrets. SafeDep links it to TeamPCP.

James RiveraMay 23, 2026
Laravel-Lang Supply Chain Attack Deploys Credential Stealer
Malware4 min read

Laravel-Lang Supply Chain Attack Deploys Credential Stealer

Attackers compromised 700+ versions of Laravel-Lang PHP packages via tag poisoning, deploying a sophisticated stealer targeting cloud credentials, crypto wallets, and browser data. Packagist pulled affected versions.

James RiveraMay 23, 2026
Nx Console VS Code Extension Hijacked for 11 Minutes
Malware4 min read

Nx Console VS Code Extension Hijacked for 11 Minutes

Attackers published malicious Nx Console 18.95.0 to VS Code Marketplace, stealing developer credentials via triple-channel exfiltration and Sigstore-signed npm package poisoning.

James RiveraMay 19, 2026
12 Critical Flaws in vm2 Node.js Sandbox Enable Host Takeover
Vulnerabilities4 min read

12 Critical Flaws in vm2 Node.js Sandbox Enable Host Takeover

Security researchers disclosed 12 sandbox escape vulnerabilities in vm2, including three with CVSS 10.0 scores. The popular JavaScript isolation library can no longer be trusted to contain untrusted code.

Marcus ChenMay 8, 2026
Vercel Breach Traced to Compromised Third-Party OAuth App
Data Breaches4 min read

Vercel Breach Traced to Compromised Third-Party OAuth App

Compromised Google Workspace OAuth app 110671459871-30f1spbu0hptbs60cb4vsmv79i7bbvqj breached Vercel, exposing API keys and source code. Hackers demand $2M; audit Workspace apps and rotate credentials.

Sarah MitchellApr 19, 2026
36 Fake Strapi Plugins Deploy Redis RCE and Credential Stealers
Malware4 min read

36 Fake Strapi Plugins Deploy Redis RCE and Credential Stealers

Coordinated npm supply chain attack deploys 36 malicious packages masquerading as Strapi CMS plugins. Attackers target cryptocurrency platforms with Redis exploitation, credential harvesting, and persistent backdoors.

James RiveraApr 7, 2026
TeamPCP Hijacks Checkmarx KICS Using Stolen Trivy Tokens
Malware4 min read

TeamPCP Hijacks Checkmarx KICS Using Stolen Trivy Tokens

Stolen CI credentials from Trivy breach enabled TeamPCP to compromise Checkmarx KICS GitHub Actions, poisoning all 35 version tags with credential-stealing malware in four-hour window.

James RiveraMar 25, 2026
CanisterWorm Adds Iran-Targeting Kubernetes Wiper
Malware4 min read

CanisterWorm Adds Iran-Targeting Kubernetes Wiper

TeamPCP's supply chain attack expands with a Kubernetes wiper that detects Iranian systems via timezone and locale, wiping clusters while backdooring everyone else.

James RiveraMar 23, 2026
Rapid7 Links Notepad++ Breach to Lotus Blossom APT
Malware5 min read

Rapid7 Links Notepad++ Breach to Lotus Blossom APT

Rapid7 attributes the six-month Notepad++ supply chain compromise to Chinese APT Lotus Blossom, revealing a custom Chrysalis backdoor and three distinct infection chains.

James RiveraFeb 6, 2026