Threats Tagged 'supply-chain attack'
View all threats tagged with 'supply-chain attack'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'supply-chain attack'
Click on any threat for detailed analysis and mitigation recommendations
Socket detected 84 compromised TanStack npm package artifacts modified with credential-stealing malware targeting CI systems, including GitHub Actions. Affected packages like @tanstack/react-router have over 12 million weekly downloads. The malicious versions contain router_init.js, a heavily obfuscated file with daemonization capabilities and environment variable access for GitHub Actions secrets. The compromise exploited GitHub Actions cache poisoning and pull_request_target patterns to extract OIDC tokens and authenticate malicious npm publishes through trusted-publisher bindings. The malware harvests credentials from GitHub Actions, AWS (IMDS, Secrets Manager, SSM), HashiCorp Vault, and Kubernetes, while establishing persistence in Claude Code and VS Code directories. Exfiltration occurs through Session's decentralized P2P network. The campaign includes self-propagation mechanisms that steal npm OIDC tokens and autonomously republish compromised packages. Updates indicate expansion to OpenSearch, Mistr... Join the discussion | AlienVault OTX General | 05/12/2026, 13:55:20 UTC Added: 05/12/2026, 16:51:32 UTC |
North Korea-aligned APT group ScarCruft executed a multiplatform supply-chain attack targeting ethnic Koreans in China's Yanbian region, an area significant for North Korean refugees and defectors. Since late 2024, the group compromised a video gaming platform dedicated to Yanbian-themed games, trojanizing both Windows and Android components with the BirdCall backdoor. The Windows client received malicious updates leading to RokRAT and subsequently BirdCall deployment, while Android games were directly trojanized. This marks the first discovery of Android BirdCall, capable of comprehensive surveillance including data collection, screenshots, and voice recording. The campaign focuses on espionage against individuals of interest to the North Korean regime, particularly refugees and defectors. Join the discussion | AlienVault OTX General | 05/05/2026, 10:23:53 UTC Added: 05/05/2026, 10:36:23 UTC |
TeamPCP launched a sophisticated attack on the Telnyx Python SDK, publishing malicious versions 4.87.1 and 4.87.2 to PyPI. The attack represents an evolution from their previous LiteLLM campaign, incorporating WAV-based steganography, split-file code injection, and expanded platform support. The payload, activated on import, uses stealthy techniques to download and execute credential-stealing malware across Linux, macOS, and Windows systems. Key changes include the use of audio steganography to hide malicious code, improved evasion through split-file injection, and the addition of Windows support with Startup folder persistence. The attackers shifted from HTTPS to plaintext HTTP infrastructure, potentially exposing their activities to network monitoring. Organizations are advised to downgrade to the last clean version and treat affected systems as compromised. Join the discussion | AlienVault OTX General | 03/30/2026, 18:06:14 UTC Added: 03/30/2026, 21:38:16 UTC |
GrayCharlie, a threat actor active since mid-2023, compromises WordPress sites to inject links redirecting visitors to NetSupport RAT payloads via fake browser updates or ClickFix mechanisms. These infections often lead to Stealc and SectopRAT deployments. The group's infrastructure is primarily linked to MivoCloud and HZ Hosting Ltd. A cluster of US law firm sites was compromised around November 2025, possibly through a supply-chain attack. GrayCharlie uses two main attack chains: one involving fake browser updates and another using ClickFix-style lures. The group's objectives appear to focus on data theft and financial gain, with potential access selling to other threat actors. Join the discussion | AlienVault OTX General | 02/18/2026, 16:28:06 UTC Added: 02/18/2026, 19:26:13 UTC |
Shai-Hulud 2.0 is a highly aggressive and automated supply-chain malware targeting the npm ecosystem, identified in November 2025. It rapidly compromises hundreds of npm packages within hours, behaving like a worm that harvests credentials and cloud secrets. The malware leverages GitHub Actions as a persistent backdoor and creates public repositories to exfiltrate stolen data. This attack represents a significant escalation in supply-chain attack sophistication, affecting major projects and organizations globally. It results in tens of thousands of attacker-created GitHub repositories, facilitating widespread propagation. The malware automates spreading to new npm accounts, increasing infection speed and scale. It does not require user interaction once initial compromise occurs and exploits trusted software supply chains. No CVE or patch is currently available, and no known exploits in the wild have been reported yet. The attack’s medium severity rating may underestimate its potential impact given its worm-like behavior and credential theft capabilities. Join the discussion | AlienVault OTX General | 11/27/2025, 03:00:54 UTC Added: 11/27/2025, 08:54:23 UTC |
Socket's research team discovered a supply-chain attack targeting Go developers through three malicious modules: prototransform, go-mcp, and tlsproxy. These modules used obfuscation techniques to deliver a disk-wiping payload, exploiting the open nature of Go's ecosystem. The attack leveraged namespace confusion and array-based string obfuscation to appear legitimate. Upon execution, the payload fetched a destructive shell script that irreversibly overwrote the entire primary storage device with zeros, causing complete data loss and system failure. This attack highlights the critical need for proactive security measures in software supply chains, especially for projects relying on external open-source dependencies. Join the discussion | AlienVault OTX General | 05/02/2025, 20:25:07 UTC Added: 06/01/2025, 20:13:22 UTC |
Showing 1 to 6 of 6 results