← BACK TO FEED
TAG

supply chain security6 articles

North Korean Hackers Hijack 108 Packages Across npm, Go and Chrome in Sprawling PolinRider Campaign

North Korean threat actors linked to the Contagious Interview campaign have published 108 malicious packages and browser extensions across npm, Packagist, Go, and Google Chrome as part of an ongoing operation called PolinRider, which has compromised nearly 2,000 public GitHub repositories. The attackers use obfuscated JavaScript payloads, fake font files, and VS Code task files to deliver malware including BeaverTail, DEV#POPPER RAT, and OmniStealer, while rewriting Git history to make malicious changes appear legitimate and harder to detect. Developers are advised to treat any affected environments as fully compromised, rotate secrets, rebuild from clean lockfiles, and audit repositories for suspicious modifications to configuration files.

9 Jul 2026

Supply Chain Attack Hits Packagist: Eight PHP Packages Compromised via GitHub-Delivered Malware

Eight packages on Packagist, the primary dependency registry for PHP projects, were quietly backdoored in a supply chain attack that used GitHub infrastructure to serve Linux malware.

25 May 2026

Megalodon Attack Poisons Thousands of GitHub Repos via CI/CD Hijacking

Someone has been systematically targeting GitHub repositories at scale.

22 May 2026

Typosquatting Has Outgrown the User Error Excuse

Typosquatting was once seen as a relatively simple phishing threat: a user mistypes a domain, lands on a malicious site, and becomes compromised. That model is now outdated. Modern typosquatting has moved beyond browsers into software package registries, dependency managers, and CI/CD pipelines, making it a software supply chain security issue rather than a user-awareness problem.

20 May 2026

A Poisoned VS Code Extension Just Breached 3,800 GitHub Repositories

GitHub has confirmed that approximately 3,800 internal repositories were compromised after an employee installed a malicious VS Code extension, which was subsequently removed from the VS Code Marketplace and the affected device secured. The hacker group TeamPCP has claimed responsibility, advertising the stolen data on a cybercrime forum for at least $50,000, though GitHub states there is no evidence that customer data outside the breached repositories was affected. This incident is part of a broader pattern of malicious VS Code extensions targeting developers, with TeamPCP also previously linked to supply chain attacks on platforms including PyPI, NPM, and Docker.

20 May 2026

OpenAI Hit by TanStack Supply Chain Attack After Two Employee Machines Infected

OpenAI confirmed it was caught up in the "Mini Shai-Hulud" npm supply chain attack, in which malware hidden in compromised TanStack packages reached two employee devices and allowed attackers to steal a limited amount of internal credentials. The two affected machines had not yet received updated supply chain security controls that would have blocked the malicious dependency. As a precaution, OpenAI is rotating signing certificates for several desktop products — including ChatGPT Desktop, Codex App, and Codex CLI — and says there is no evidence that customer data or production systems were compromised.

17 May 2026