Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > supply chain attack
#supply chain attack

BGP Hijack Poisoned Virtualizor Updates and Put Hosting Servers at Root-Level Risk

1 September 2026  |  dark6  |  Vulnerability

A routing hijack diverted Softaculous infrastructure and enabled a malicious Virtualizor update to reach a small number of hosting servers. Because update packages lacked cryptographic verification, valid TLS...

>> read more

Hijacked Rust Crates With 244 Million Downloads Turned Into Malware Delivery Pipeline

21 August 2026  |  dark6  |  Malware

A typosquatted Rust package quietly hijacked two popular crates, arrayref and append-only-vec, to run an infostealer during ordinary builds. The attack hid inside an automatically-executed build script, leaving...

>> read more

ChainDrop Worm Spreads Through 400+ npm Packages, Raiding Developer and Cloud Credentials

9 August 2026  |  dark6  |  Malware

A self-propagating worm dubbed ChainDrop has infected more than 400 npm packages by hijacking trusted publishing accounts, quietly harvesting npm, GitHub, cloud, and SSH credentials from developer machines...

>> read more

Researchers Find Matching RCE Flaws in Claude Code, Gemini CLI and Codex Coding Agents

9 August 2026  |  dark6  |  Vulnerability

Security researcher Elad Meged has uncovered a strikingly similar vulnerability pattern across AI coding agents from Anthropic, Google, and OpenAI, all traceable to how each vendor's surrounding 'harness'...

>> read more

Fake VS Code Extensions Quietly Siphoned Git and CI Secrets From Developers

6 August 2026  |  dark6  |  Malware

Seventy-seven counterfeit Open VSX extensions impersonated legitimate developer tools and quietly phoned home to a single attacker-controlled domain. Nineteen of them went further, harvesting Git repository details and...

>> read more

How One Poisoned Tracking Script Turned a Major Ad Platform Into a Crypto-Theft Pipeline

4 August 2026  |  dark6  |  Malware

Researchers say attackers hijacked a widely deployed JavaScript file from ad-tech company Adform, turning routine website analytics into a silent clipboard hijacker that swaps copied crypto wallet addresses...

>> read more

Coca-Cola’s Fairlife Brand Halts US Production After Ransomware Hits Manufacturing Systems

18 July 2026  |  dark6  |  Ransomware

Coca-Cola disclosed in an SEC filing that its Fairlife dairy subsidiary suffered a ransomware attack that forced a temporary halt of US production, while Canadian operations continued unaffected....

>> read more

Shai-Hulud Malware Expands to npm Ecosystem, Stealing Cloud and CI/CD Credentials From Developers

26 June 2026  |  dark6  |  Malware

A credential-stealing malware campaign known as Shai-Hulud has expanded to target developers using the Leo/RStreams npm package ecosystem, harvesting GitHub tokens, cloud access keys, CI/CD secrets, and SSH...

>> read more