CyberSecurityBoardThreat Intel · CVEs · Products

Tag: Supply Chain

Malware

Shai-Hulud: Historical npm Worm Activity

Shai-Hulud is a known npm worm family that has been active in past supply chain attacks. The recent ChainDrop campaign shows tradecraft…

malware npm Shai-Hulud Supply Chain
July 7, 2026
Cyber Companies

Checkmarx: Impacted by Trivy Attack

Checkmarx, a software security company, confirmed that credentials obtained through the Trivy attack enabled unauthorized access to its GitHub repositories and the…

Checkmarx GitHub Supply Chain
July 3, 2026
Cyber Products

PyPI Releases of LiteLLM Backdoored

PyPI was used to distribute backdoored LiteLLM releases. The malicious builds were removed from the index but still accessible via direct URLs.

package manager PyPI Supply Chain
July 3, 2026