CyberSecurityBoardThreat Intel · CVEs · Products

Tag: Supply Chain

Cyber Products

Keyv: npm Package and Worm Vector

Keyv is an npm package that was compromised in the August 2026 worm campaign. The malicious keyv@6.0.0 release included a preinstall script…

Keyv malware npm Supply Chain
August 4, 2026
Malware

Cross-Platform RAT Targets Alibaba Developer Tools

A sophisticated cross-platform remote access trojan (RAT) was delivered via malicious npm packages impersonating Alibaba's private packages. The RAT is capable of…

Alibaba malware RAT Remote Access Trojan (RAT)
August 3, 2026
Cyber Companies

Xanadu’s mrmustard Library Poisoned

Xanadu's photonic quantum computing Python library, mrmustard, was compromised with a poisoned version that ran an information stealer. The attack involved breaching…

information stealer mrmustard Supply Chain Xanadu
August 3, 2026
Cyber Companies

Adform

Adform is an advertising technology company that detected and responded to a supply-chain compromise of its JavaScript file trackpoint-async.js, which was used…

Adform advertising technology incident response Supply Chain
August 1, 2026
Cyber Products

Android TV Boxes: Target of Fuyao Malware

Cheap Android TV boxes, particularly models like H96_MAX_V11, are the primary devices affected by the Fuyao operation. They are shipped with malicious…

Android TV boxes IoT malware Supply Chain
July 31, 2026