Hackers pushed a poisoned arrayref version that added a dependency to fetch a malicious payload from a remote server.
The post Rust Supply Chain Attack Linked to North Korean Hackers appeared first on SecurityWeek.
Hackers pushed a poisoned arrayref version that added a dependency to fetch a malicious payload from a remote server.
The post Rust Supply Chain Attack Linked to North Korean Hackers appeared first on SecurityWeek.
Over 95% of the affected companies were exposed before the malicious LiteLLM packages were published.
The post Trivy, Not LiteLLM Behind the 2,500 Org Compromise appeared first on SecurityWeek.
LiteLLM was compromised through the Trivy hack and abused to distribute information-stealing malware to its users.
The post Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack appeared first on SecurityWeek.
The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials.
The post Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack appeared first on SecurityWeek.
A threat actor poisoned several Jscrambler NPM package versions to drop a cross-platform credential stealer.
The post Multiple Jscrambler Packages Impacted by Supply Chain Attack appeared first on SecurityWeek.
The PolinRider campaign has compromised more than 100 legitimate open source packages and repositories to deliver a backdoor and information stealer to developers.
The post North Korean Hackers Target Open Source Developers in Supply Chain Attacks appeared first on SecurityWeek.
Decades-old Bash shell tricks can bypass safeguards in most open source AI coding agents, potentially turning malicious repositories into supply chain attack vectors.
The post Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks appeared first on SecurityWeek.
Roughly two dozen companies have notified their customers of the Klue-Salesforce incident impact.
The post More Klue Breach Victims Identified as Hackers Get Hacked appeared first on SecurityWeek.
A malicious dependency the attackers added to over 140 Mastra packages fetches a payload targeting cryptocurrency extensions.
The post North Korean Hackers Blamed for Mastra NPM Supply Chain Attack appeared first on SecurityWeek.
HackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk, and Tanium are among the affected Klue customers.
The post More Cybersecurity Firms Disclose Impact From Klue Hack appeared first on SecurityWeek.