← All articles

supply chain

19 articles

CVEweb securitysupply chainremediationdevelopment

CVE-2026-45618: Your Template Engine Runs Arbitrary Code. CVSS 10.

LiquidJS, a templating library with 7 million monthly downloads, lets attackers run any code on your server through a crafted template string. No login required. Public exploit available.

Jun 4, 2026
supply chainTeamPCPinfrastructuresmall business

Malware Got Pushed Directly to Microsoft's GitHub. Yours Could Be Next.

A single compromised account pushed malicious code to 42 repos across Microsoft and Azure GitHub orgs in under an hour. If you trust code because of who published it, that trust is now a liability.

Jun 4, 2026
supply chainnpmsmall businessremediation

npm install Just Ran Malware on Your Machine. You Didn't Even Know.

A self-propagating worm is using a blind spot in npm's native build system to execute code the moment you install a package. No install scripts. No warnings. Just binding.gyp.

Jun 3, 2026
supply chainsource codeGitHubcredential abuseremediation

They Validated Your GitHub Tokens. Now They're Cloning Your Repos.

The token-checking campaign we warned about two weeks ago has entered phase two. Attackers are mass-cloning private repositories using stolen PATs. Your source code is walking out the door.

Jun 2, 2026
TeamPCPsupply chainCVEsmall business

TeamPCP: The Supply Chain Attackers Who Won't Stop

7 waves. 170+ packages. VS Code extensions. Jenkins plugins. A self-propagating worm. And they breached GitHub itself. Here's the full timeline of the most prolific supply chain campaign of 2026.

Jun 1, 2026
supply chainTeamPCPsmall businessremediation

Red Hat's npm Packages Were Stealing Your Credentials. Yes, Red Hat.

29 packages under the @redhat-cloud-services namespace were compromised with a self-propagating credential stealer. 80,000 weekly downloads. If Red Hat's packages aren't safe, neither are yours.

May 31, 2026
CVEsupply chainremediationsmall businessFortinet

CVE-2026-35616: Your Security Tool Just Installed Malware on Every Device

Attackers exploited FortiClient EMS to push a credential stealer disguised as a Fortinet firmware update. Your endpoint management system delivered the malware for them. You can't make this up.

May 29, 2026
supply chainCVEsecurity operationsTeamPCP

Stop Auto-Updating Everything. Seriously.

The biggest supply chain attack in npm history just happened. 160+ packages compromised. If you had auto-updates on, you swallowed the poison automatically. Here's what to do instead.

May 28, 2026
supply chainTeamPCPremediationinfrastructure

Someone Is Checking If Your GitHub Tokens Still Work. Right Now.

Mass automated validation of stolen GitHub PATs from bulletproof hosting. They're testing which tokens are live, what scopes they have, and triaging the valuable ones. Revoke your old tokens today.

May 27, 2026
social engineeringthreat actordeveloper securitymacOSsupply chain

That Recruiter in Your DMs Is Installing Malware on Your Mac

A threat actor called JINX-0164 is posing as recruiters to trick developers into running malware that steals credentials, crypto wallets, and SSH keys. If your company employs developers, this is your problem.

May 26, 2026
supply chainVSCodeCVETeamPCP

Your Code Editor Just Became a Backdoor. Here's What Happened.

A poisoned VS Code extension breached GitHub's internal repos. 3,800 repositories. 18 minutes. If you install extensions without thinking, you need to read this.

May 21, 2026
supply chainPyPIsmall businessremediation

Another PyPI Package Was a Trojan Horse. This One Had a Wiper.

Microsoft's official Durable Task Python SDK was hijacked on PyPI with a credential stealer, a Linux file wiper, and worm logic that spreads using your own cloud keys. No CVE was assigned. Most scanners missed it.

May 18, 2026
supply chainTeamPCPsmall businessremediation

node-ipc Backdoored Through an Expired Domain. 10 Million Weekly Downloads.

An attacker registered a co-maintainer's expired email domain, reset the npm password, and published a credential stealer that exfiltrates over DNS. No hack required. Just a $12 domain registration.

May 15, 2026
CVETeamPCPsupply chainremediation

TeamPCP Backdoored a Security Scanner. Your Security Tools Are the Target.

The Checkmarx Jenkins plugin, installed to find vulnerabilities in your code, was itself compromised with an infostealer. CVE-2026-33634. CVSS 9.4. Every secret in your CI/CD pipeline was exfiltrated.

May 10, 2026
WordPressweb securitysupply chain

Your WordPress Site Is Probably Already Compromised

30-40% of WordPress sites are running plugins with known vulnerabilities. A supply chain attack just backdoored 400,000 sites through trusted plugin updates. If you run WordPress, read this.

May 4, 2026
supply chainCI/CDPythonGitHub Actionsremediation

A GitHub Comment Backdoored a Python Package. Read That Again.

An attacker posted a comment on a pull request. Twelve hours later, every data engineer running elementary-data 0.23.3 was exfiltrating their warehouse credentials to a stranger. Your CI/CD pipeline is a factory floor with no locks on the doors.

Apr 23, 2026
supply chainAIsmall businessinfrastructureVercel

Vercel Got Breached Through an AI Tool. Your SaaS Vendors Are Next.

An infostealer at a third-party AI company led to Vercel customer secrets being exposed. The attack chain: AI tool employee gets malware, attacker pivots to Vercel, customer API keys and DB credentials decrypted. Two months undetected.

Apr 20, 2026
supply chainsocial engineeringsmall business

ShinyHunters Stole a Petabyte From Telus. Through a Chatbot.

The breach started with stolen OAuth tokens from a chatbot integration. ShinyHunters pivoted through Salesforce, found GCP credentials, and exfiltrated nearly 1 petabyte including FBI background checks and customer call recordings.

Mar 13, 2026
small businesssupply chainassessment

The SaaS Tools Your Team Uses Are a Liability

The average small business uses 47 SaaS apps. Each one stores data, holds credentials, and connects to other services. Most have no security oversight. Here's why that's a problem you need to solve.

Jan 27, 2026