Supply Chain Security
26 articles RSS
Two GitHub Actions Disabled Since May's Mini Shai-Hulud Compromise Came Back Online in September, Reactivating Malware With No New Attack
Socket found that actions-cool/issues-helper and actions-cool/maintain-one-comment, disabled since May 2026, became reachable again on September 16 with their malicious tags intact, silently re-running the payload.
Malicious npm Package Bypasses Install-Script Defenses, Hides Malware Inside Runtime Code
The indexed-btree npm package evades npm v12's install-script blocking by hiding its malware loader inside a runtime method instead, Checkmarx reports.
PolinRider Campaign Hits Packagist, Planting Malware in a 700,000-Download Laravel Nova Package
Socket found malicious code in dev branches of a 700,000-download Laravel Nova package on Packagist, tying the compromise to its ongoing PolinRider campaign.
GemStuffer Campaign Exploited RubyGems' Documentation-Build Pipeline for RCE and a CVSS 7.3 CDN Caching Flaw
A research report ties a May 2026 RubyGems package-flooding campaign to OpenAI agents that abused a documentation-build RCE and probed a since-patched CDN key-leak bug.
vlt Reaches 1.0, Launching Hosted Package Registries as a Security-First npm Replacement
vlt, a JavaScript package manager built by npm's original developers, ships 1.0 with hosted registries that block malware and phased installs that stop scripts from running automatically.
24 Malicious npm Packages Abuse Unpkg and Other Mirrors to Host Fake Cloudflare CAPTCHA Pages
OX Security found 24 npm packages built solely to let mirrors like unpkg serve fake Cloudflare CAPTCHA pages that can redirect to ClickFix-style phishing.
New Study Finds RAG and Self-Refine Are the Only Defenses That Hold Up Against Adversarial AI Package Hallucination Attacks
A new paper testing seven defenses against AI-hallucinated software packages finds only RAG and Self-Refine hold up under adversarial prompting; Ruby stays the most vulnerable language.
Trojanized npm Packages Deliver AI-Assisted RedC2 4.0 Linux Backdoor, Trend Micro Finds
TrendAI found 14 npm packages disguised as calendar utilities quietly installing RedShell, a Linux implant tied to the AI-assisted RedC2 4.0 command-and-control framework.
Flux Mirror Plugin Turns Container Registries Into a 'Supply-Chain Diode' for Gitless GitOps
Flux's new CLI plugin mirrors images, Helm charts, and OCI artifacts into registries teams control, holding back newly signed artifacts to blunt fast-moving supply-chain attacks.
Socket Launches Firefox Extension Scanning After Uncovering 77-Extension Crypto Wallet-Theft Network
Socket added Firefox extension scanning for enterprise customers days after its researchers uncovered 40 malicious extensions stealing crypto wallet secrets.
Rust Security Team Locks Compromised arrayref Crate After Malicious proc-macro1 Package Reaches Crates.io
Rust's security team removed a malicious proc-macro1 crate and the arrayref, internment, and append-only-vec crates it compromised, each pulled from crates.io within about 90 minutes.
StubMaker Malware Campaign Hit RubyGems and npm With the Same Windows Infostealer
Researchers found one threat actor ran typosquatting campaigns on RubyGems and npm days apart, sharing an identical Rust loader and Go infostealer.