Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > supply chain attack
#supply chain attack

GitHub Confirms Internal Repository Breach via Malicious VS Code Extension — TeamPCP Claims 3,800 Repos Stolen

20 May 2026  |  dark6  |  Databreach

GitHub has confirmed unauthorized access to its internal repositories after a malicious Visual Studio Code extension compromised an employee device. Threat actor TeamPCP claims to have exfiltrated approximately...

>> read more

JDownloader Official Website Hijacked to Deliver RAT Malware in Windows and Linux Installers

17 May 2026  |  dark6  |  Malware

Attackers compromised the official JDownloader website between May 6-7, 2026, replacing legitimate Windows and Linux installers with malicious versions containing a Python-based Remote Access Trojan. Users who downloaded...

>> read more

TeamPCP Supply Chain Campaign Poisons Checkmarx KICS, Bitwarden CLI, and PyPI Packages to Steal Cloud Credentials at Scale

16 May 2026  |  dark6  |  Cybercrime

A financially motivated threat group tracked as TeamPCP has executed at least seven waves of sophisticated supply chain attacks since March 2026, poisoning trusted CI/CD tools including Checkmarx...

>> read more

84 TanStack npm Packages Poisoned in Sophisticated Supply-Chain Attack Stealing Cloud and CI Credentials

15 May 2026  |  dark6  |  Cybercrime

Attackers compromised 84 npm artifacts across 42 TanStack packages — including react-router with 12M+ weekly downloads — injecting a credential-stealing payload via chained GitHub Actions abuse. Organizations that...

>> read more

Foxconn Confirms Cyberattack: Nitrogen Ransomware Gang Claims 8TB Stolen From North American Plants

14 May 2026  |  dark6  |  Ransomware

Foxconn has confirmed a ransomware attack on its North American factories after the Nitrogen gang claimed to have stolen 8TB of data including technical drawings and network topology...

>> read more

DigiCert Breached via Weaponized Screensaver: Threat Actor Steals EV Code Signing Certificates to Spread Zhong Stealer

7 May 2026  |  dark6  |  Databreach

A sophisticated threat actor breached DigiCert's internal support environment in early April 2026 by tricking analysts into executing a disguised .scr malware file, ultimately obtaining EV Code Signing...

>> read more

Trellix Source Code Breach: Hackers Gain Unauthorized Access to Internal Repository of Major XDR Vendor

3 May 2026  |  dark6  |  Databreach

Cybersecurity vendor Trellix has confirmed unauthorized access to part of its internal source code repository. The company says no evidence of product tampering or active exploitation has been...

>> read more

Bitwarden CLI npm Package Compromised in Sophisticated GitHub Actions Supply Chain Attack

28 April 2026  |  dark6  |  Malware

Security researchers at Socket have confirmed that the official Bitwarden CLI npm package (version 2026.4.0) was tampered with via a compromised GitHub Actions workflow, injecting credential-stealing malware as...

>> read more