Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > supply chain attack
#supply chain attack

ChainDrop Worm Spreads Through 400+ npm Packages, Raiding Developer and Cloud Credentials

9 August 2026  |  dark6  |  Malware

A self-propagating worm dubbed ChainDrop has infected more than 400 npm packages by hijacking trusted publishing accounts, quietly harvesting npm, GitHub, cloud, and SSH credentials from developer machines...

>> read more

Researchers Find Matching RCE Flaws in Claude Code, Gemini CLI and Codex Coding Agents

9 August 2026  |  dark6  |  Vulnerability

Security researcher Elad Meged has uncovered a strikingly similar vulnerability pattern across AI coding agents from Anthropic, Google, and OpenAI, all traceable to how each vendor's surrounding 'harness'...

>> read more

Fake VS Code Extensions Quietly Siphoned Git and CI Secrets From Developers

6 August 2026  |  dark6  |  Malware

Seventy-seven counterfeit Open VSX extensions impersonated legitimate developer tools and quietly phoned home to a single attacker-controlled domain. Nineteen of them went further, harvesting Git repository details and...

>> read more

How One Poisoned Tracking Script Turned a Major Ad Platform Into a Crypto-Theft Pipeline

4 August 2026  |  dark6  |  Malware

Researchers say attackers hijacked a widely deployed JavaScript file from ad-tech company Adform, turning routine website analytics into a silent clipboard hijacker that swaps copied crypto wallet addresses...

>> read more

Coca-Cola’s Fairlife Brand Halts US Production After Ransomware Hits Manufacturing Systems

18 July 2026  |  dark6  |  Ransomware

Coca-Cola disclosed in an SEC filing that its Fairlife dairy subsidiary suffered a ransomware attack that forced a temporary halt of US production, while Canadian operations continued unaffected....

>> read more

Shai-Hulud Malware Expands to npm Ecosystem, Stealing Cloud and CI/CD Credentials From Developers

26 June 2026  |  dark6  |  Malware

A credential-stealing malware campaign known as Shai-Hulud has expanded to target developers using the Leo/RStreams npm package ecosystem, harvesting GitHub tokens, cloud access keys, CI/CD secrets, and SSH...

>> read more

Klue Supply Chain Hack Exposes Salesforce Data at Nine Cybersecurity Companies

23 June 2026  |  dark6  |  Databreach

A supply chain attack on market intelligence platform Klue has compromised Salesforce CRM data across at least nine organizations, including HackerOne, Huntress, and Recorded Future. The Icarus extortion...

>> read more

Supply Chain Attack Compromises 140+ Mastra npm Packages, Targeting Developer Credentials and Crypto Wallets

18 June 2026  |  dark6  |  Malware

A sophisticated supply chain attack has compromised over 141 packages in the Mastra-AI npm ecosystem, including @mastra/core which sees 918,000 weekly downloads. Detected on June 17, 2026, the...

>> read more