ChainDrop Worm Compromises npm Supply Chain with Stealthy Techniques

A new variant of the Shai-Hulud npm worm, named ChainDrop, has infected 444 packages, employing unique methods to evade detection and compromise repositories.

A new variant of the Shai-Hulud npm worm, named ChainDrop, has infected 444 packages, employing unique methods to evade detection and compromise repositories.

A supply chain attack has led to the compromise of multiple Pro plugins from ShapedPlugin, affecting users who installed updates through official channels.

A single attacker has published 14 malicious npm packages impersonating popular libraries, raising concerns about supply chain security.

A coordinated supply chain attack named TrapDoor has been identified, targeting npm, PyPI, and Crates.io to spread credential-stealing malware through numerous malicious packages.

A new automated malware campaign named Megalodon has compromised more than 5,500 GitHub repositories, raising concerns over supply chain security.

Grafana Labs has reported a breach of its GitHub environment, revealing source code and internal information but confirming no compromise of customer production systems.

OpenAI has disclosed a security incident involving the theft of internal credentials due to compromised employee devices, part of a broader supply chain attack affecting npm ecosystems.

Recent findings reveal that Vect's ransomware is actually a data wiper, rendering recovery impossible for affected organizations.

Checkmarx confirms data exposure linked to a supply chain attack, with Lapsus$ claiming responsibility for the breach.

Recent findings reveal that malicious Docker images and Visual Studio Code extensions have compromised Checkmarx's software supply chain, posing significant risks to users.