Docker Hub Used in Supply Chain Attack
Docker Hub was one of the distribution ecosystems used by TeamPCP to distribute compromised container images.
Docker Hub was one of the distribution ecosystems used by TeamPCP to distribute compromised container images.
OpenVSX, a marketplace for VS Code extensions, was one of the distribution ecosystems used by TeamPCP.
Cybersecurity researchers at OX Security have uncovered a campaign that abuses 24 npm packages as free phishing infrastructure. The packages host HTML…
DoFun is the manufacturer of Android-based automotive head unit firmware that was exploited by MoYu Group to distribute malware through built-in updaters.…
Google Threat Intelligence Group attributes the axios npm compromise to MIDNIGHT NEPTUNE, formerly known as UNC1069. The actor is linked to North…
proc-macro1 is a typosquatted dependency of the legitimate proc-macro2 crate, used in a supply chain attack against Rust crates. Its build script…
arrayref is a widely used Rust crate with over 245 million downloads. A malicious version (0.3.10) was published via a compromised maintainer…
internment is a Rust crate that was compromised in the August 2026 supply chain attack. Version 0.8.7 was published with a dependency…
append-only-vec is a Rust crate that had a malicious version (0.1.9) published during the supply chain attack. The release included a dependency…
Nextron Systems GmbH's Research Team initially discovered and reported the malicious proc-macro1 crate to the Rust Security Response Team. Their analysis detailed…