Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > supply chain attack
#supply chain attack

OceanLotus APT (APT32) Compromises FireAnt MetaKit in Targeted Supply-Chain Attack on Vietnamese Stock Investors

12 June 2026  |  dark6  |  Cybercrime

The Vietnamese state-aligned threat group OceanLotus (APT32) hijacked the update server of popular investment software FireAnt MetaKit to deliver the SPECTRALVIPER backdoor to targeted stock market users, in...

>> read more

Critical npm Supply Chain Attack: Malicious ‘dbmux’ Package Gives Hackers Full System Control

11 June 2026  |  dark6  |  Malware

A malicious npm package named dbmux was discovered containing malware that gives attackers complete control over any developer system that installed it. Part of a coordinated wave of...

>> read more

Hackers Can Hijack Claude Code MCP Traffic to Steal OAuth Tokens — No Patch Coming

8 June 2026  |  dark6  |  Cybercrime

Researchers at Mitiga Labs demonstrated a five-step npm supply chain attack that rewrites ~/.claude.json to redirect Claude Code MCP traffic through attacker-controlled infrastructure, silently capturing OAuth tokens for...

>> read more

Critical Supply Chain Attack: 31 Red Hat Cloud Services npm Packages Backdoored to Steal Cloud and Dev Credentials

2 June 2026  |  dark6  |  Cybercrime

A sophisticated supply chain attack dubbed "Miasma: The Spreading Blight" has backdoored over 30 official @redhat-cloud-services npm packages, deploying credential-stealing malware that targets AWS, Azure, GCP secrets, GitHub...

>> read more

Attackers Exploit Docker and Kubernetes Misconfigurations to Escape Containers and Seize Host Control

2 June 2026  |  dark6  |  Vulnerability

Security researchers have documented a wave of attacks exploiting Docker and Kubernetes misconfigurations to break out of containers and take full control of host systems, including supply chain...

>> read more

Massive Supply Chain Attack: Poisoned VS Code Extension and “Megalodon” Campaign Steal Credentials from Millions of Developers

1 June 2026  |  dark6  |  Cybercrime

Two coordinated supply chain attacks poisoned the Nx Console VS Code extension (2.2M installs) and backdoored 5,561 GitHub repositories simultaneously, stealing cloud credentials and 3,800 internal GitHub source...

>> read more

Malicious npm Package forge-jsxy Pushes 22 Versions in 22 Days to Steal Crypto Wallets and Deploy Persistent Backdoor

29 May 2026  |  dark6  |  Malware

The npm package forge-jsxy quietly stole cryptocurrency wallet keys, browser credentials, and developer data across Windows, macOS, and Linux — publishing 22 malicious versions in 22 days, and...

>> read more

Grafana GitHub Breach: TanStack npm Supply Chain Attack Leads to Source Code Theft and Ransom Demand

27 May 2026  |  dark6  |  Databreach

Grafana Labs has confirmed a ransomware-linked breach of its GitHub environment traced to the TanStack npm supply chain compromise. Attackers exfiltrated internal source code repositories and issued a...

>> read more