← BACK TO FEED
TAG

supply chain attack8 articles

North Korean Hackers Poisoned One of Rust's Most Downloaded Packages

North Korean hackers, likely the group Sapphire Sleet, carried out a supply chain attack on the Rust ecosystem on August 20, compromising the widely-used *arrayref* crate by publishing a malicious version from its legitimate maintainer's hijacked account. The poisoned package contained a hidden build script designed to fetch a malicious second-stage binary, with the attack also spreading to several other related crates. The Rust Security Response Team removed all malicious packages within 86 minutes, found no evidence of actual usage, and linked the incident to previous North Korean-attributed NPM attacks based on shared infrastructure.

22 Aug 2026

Poisoned Rust Packages Spent 90 Minutes Stealing Developer Credentials Before Anyone Noticed

Hackers injected malware into several popular Rust packages, including arrayref, internment, and append-only-vec, by compromising a developer's credentials and publishing poisoned versions that fetched second-stage malware capable of stealing browser data, cryptocurrency wallet information, and establishing persistent remote access. The malicious releases were live for under two hours before the Rust Security Response Team removed them, though arrayref's roughly 245 million lifetime downloads highlights the potential reach of such an attack. Developers have been advised to audit their Cargo lockfiles and local registry caches for the affected packages.

22 Aug 2026

N-able's N-central Authentication Bypass Gets Patched Twice After First Fix Left Door Open

Attackers exploited an authentication bypass vulnerability (CVE-2026-18556/CVE-2026-18577) in N-able's N-central remote monitoring platform to gain administrative access to servers and then pivot to managed customer endpoints using the platform's Take Control feature. They also installed persistent Cloudflare tunnels on compromised devices, meaning that simply upgrading N-central is insufficient — customers must also actively hunt for and remove malicious tunnel services. N-able's initial patch proved incomplete, and the fully fixed version (build 2026.3.1.7) was released on August 2, with self-hosted customers required to upgrade manually.

3 Aug 2026

Iranian APT Cavern Manticore Is Running a Modular Hacking Framework Built With Suspicious AI Assistance

An Iran-linked APT group called Cavern Manticore, likely tied to Iran's Ministry of Intelligence and Security, has been conducting cyberattacks against Israeli government entities and IT providers using a modular C&C framework built in .NET. The framework is designed to evade analysis by using multiple compilation formats rather than traditional obfuscation, and isolates modules in separate memory domains that are wiped after use to eliminate forensic artifacts. The group demonstrates a sophisticated understanding of Israel's IT supply chains, using compromised IT providers as stepping stones to reach intended targets.

14 Jul 2026

Red Hat npm Packages Backdoored in Supply Chain Attack Stealing Cloud Credentials

Over 30 npm packages under Red Hat's '@redhat-cloud-services' namespace were backdoored in a supply-chain attack, after attackers compromised a Red Hat employee's GitHub account and used it to publish malicious package versions containing credential-stealing malware. The malware, dubbed "Miasma," is a variant of the Shai-Hulud framework and was designed to steal a wide range of sensitive data including cloud credentials, SSH keys, CI/CD tokens, and environment files from developers who installed the affected packages. Red Hat removed the compromised packages and stated that they were limited to internal development tooling with no confirmed impact on customer environments, though the investigation remains ongoing.

3 Jun 2026

How One Unrotated Token Gave Hackers Access to Grafana's Codebase

Grafana's data breach stemmed from a single GitHub workflow token that was accidentally missed during a credential rotation following the TanStack npm supply-chain attack, in which malicious packages infected with credential-stealing malware exfiltrated tokens from Grafana's CI/CD environment. The overlooked token allowed attackers to access private repositories, from which they stole source code and internal business contact information, though no customer production data or systems were compromised. Grafana confirmed that its codebase was not modified during the incident, meaning downloaded code remains safe, and users are not required to take any action.

21 May 2026

Another npm Account Hijacked, 314 Packages Poisoned in Under Half an Hour

A compromised npm account infected 314 JavaScript packages — including popular ones like size-sensor and echarts-for-react with millions of monthly downloads — with malware that steals credentials for cloud platforms, GitHub, and npm, and uses GitHub as a command-and-control backdoor. The attack, which unfolded in just 22 minutes, follows the same pattern as a similar incident three weeks ago and is part of an ongoing wave of npm supply chain attacks dubbed "Shai-Hulud." Developers who installed affected versions are advised to rotate all credentials, while npm owner GitHub has said little about the continuing series of incidents.

20 May 2026

One Dodgy VS Code Extension Later, GitHub Lost 3,800 Internal Repos

GitHub confirmed that approximately 3,800 internal repositories were compromised in a supply chain attack carried out by the hacking group TeamPCP, after an employee installed a malicious VS Code extension on their machine. The attackers claimed to have stolen source code and internal data, offering it for sale for at least $50,000 on an underground forum. GitHub responded by rotating critical credentials and launching an investigation, noting that the attack highlights the significant security risk posed by unvetted developer tools and extensions.

20 May 2026