Poisoned mrmustard Library Delivers Information Stealer
A poisoned version of the mrmustard Python library from Xanadu was published to run an information stealer that harvests SSH keys, AWS…
A poisoned version of the mrmustard Python library from Xanadu was published to run an information stealer that harvests SSH keys, AWS…
A sophisticated cross-platform remote access trojan (RAT) was delivered via malicious npm packages impersonating Alibaba's private packages. The RAT is capable of…
Alibaba Group's developer tools were targeted in a software supply chain attack via malicious npm packages impersonating private @ali-scoped packages. The attack…
Adform is an advertising technology company that detected and responded to a supply-chain compromise of its JavaScript file trackpoint-async.js, which was used…
Cybersecurity firm Bitsight has uncovered a large-scale operation dubbed 'Fuyao' involving cheap Android TV boxes that secretly impersonate smartphones to commit ad…
Cheap Android TV boxes, particularly models like H96_MAX_V11, are the primary devices affected by the Fuyao operation. They are shipped with malicious…
INL was cited in the FCC determination for its research on supply-chain and remote-connectivity risks related to power inverters.
Evidence suggests infrastructure overlaps between the Rust crate supply chain attacks and prior attacks targeting Mastra and Axios, both linked to North…
RubyGems is the official package registry for Ruby. It was targeted by a typosquatting campaign that exploited package name reuse and unvalidated…
SQL Server Management Studio was used as a lure in a supply chain attack, where a fake installer actually delivered trojanized Audacity…