Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > supply chain attack
#supply chain attack

105 Minutes of Stolen Access Turned a Trusted npm Package Into a Multi-Stage Malware Loader

23 September 2026  |  dark6  |  Malware

Attackers hijacked a maintainer account for just 105 minutes to slip a hidden loader into a popular npm package, abusing legitimate publishing infrastructure so the poisoned release carried...

>> read more

Popular npm Package With Nearly 2 Million Weekly Downloads Hid Malware That Talks to Attackers Through Ethereum

22 September 2026  |  dark6  |  Malware

Researchers at Checkmarx uncovered a supply-chain campaign hiding inside a widely used npm package that impersonates a legitimate data-structure library. Rather than infecting machines at install time, the...

>> read more

BGP Hijack Poisoned Virtualizor Updates and Put Hosting Servers at Root-Level Risk

1 September 2026  |  dark6  |  Vulnerability

A routing hijack diverted Softaculous infrastructure and enabled a malicious Virtualizor update to reach a small number of hosting servers. Because update packages lacked cryptographic verification, valid TLS...

>> read more

Hijacked Rust Crates With 244 Million Downloads Turned Into Malware Delivery Pipeline

21 August 2026  |  dark6  |  Malware

A typosquatted Rust package quietly hijacked two popular crates, arrayref and append-only-vec, to run an infostealer during ordinary builds. The attack hid inside an automatically-executed build script, leaving...

>> read more

ChainDrop Worm Spreads Through 400+ npm Packages, Raiding Developer and Cloud Credentials

9 August 2026  |  dark6  |  Malware

A self-propagating worm dubbed ChainDrop has infected more than 400 npm packages by hijacking trusted publishing accounts, quietly harvesting npm, GitHub, cloud, and SSH credentials from developer machines...

>> read more

Researchers Find Matching RCE Flaws in Claude Code, Gemini CLI and Codex Coding Agents

9 August 2026  |  dark6  |  Vulnerability

Security researcher Elad Meged has uncovered a strikingly similar vulnerability pattern across AI coding agents from Anthropic, Google, and OpenAI, all traceable to how each vendor's surrounding 'harness'...

>> read more

Fake VS Code Extensions Quietly Siphoned Git and CI Secrets From Developers

6 August 2026  |  dark6  |  Malware

Seventy-seven counterfeit Open VSX extensions impersonated legitimate developer tools and quietly phoned home to a single attacker-controlled domain. Nineteen of them went further, harvesting Git repository details and...

>> read more

How One Poisoned Tracking Script Turned a Major Ad Platform Into a Crypto-Theft Pipeline

4 August 2026  |  dark6  |  Malware

Researchers say attackers hijacked a widely deployed JavaScript file from ad-tech company Adform, turning routine website analytics into a silent clipboard hijacker that swaps copied crypto wallet addresses...

>> read more