Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 90 results
Active filter:tag: #supply-chain✕ clear
Poisoned npm package compromises 140+ projects via postinstall payloadhighbug_reportVulnerability
bug_reportVulnerability

Poisoned npm package compromises 140+ projects via postinstall payload

140+ projects using a malicious npm package containing a hidden postinstall script. Affects Node.js/JavaScript development environments consuming npm dependencies. Specific package name not disclosed in summary.

npm18 Jun · 01:43 UTC
Supply chain attack compromises 144 Mastra npm packages via hijacked accountcriticalbug_reportVulnerability
bug_reportVulnerability

Supply chain attack compromises 144 Mastra npm packages via hijacked account

144 npm packages in the @mastra/* namespace (Mastra AI framework for JavaScript/TypeScript). Attack vector: compromised npm contributor account (ehindero). All downstream projects using affected Mastra packages are potentially impacted.

Mastra17 Jun · 05:38 UTC
Malicious JetBrains IDE plugins steal AI API keys from developershighbug_reportVulnerability
bug_reportVulnerability

Malicious JetBrains IDE plugins steal AI API keys from developers

JetBrains Marketplace users who installed any of the 15+ malicious plugins. Affects developers using JetBrains IDEs (IntelliJ IDEA, PyCharm, WebStorm, etc.) with AI API keys configured. Specific plugin names and versions not provided in summary.

JetBrains16 Jun · 19:54 UTC
Awesome Motive CDN breach compromises WordPress plugins in supply-chain attackhighbug_reportVulnerability
bug_reportVulnerability

Awesome Motive CDN breach compromises WordPress plugins in supply-chain attack

WordPress plugins OptinMonster, TrustPulse, and PushEngage distributed via Awesome Motive's CDN. All versions served through the compromised CDN infrastructure are potentially affected.

Awesome Motive15 Jun · 15:37 UTC
Supply chain attack hits PushEngage, OptinMonster, TrustPulse pluginscriticalbug_reportVulnerability
bug_reportVulnerability

Supply chain attack hits PushEngage, OptinMonster, TrustPulse plugins

WordPress sites using PushEngage, OptinMonster, and TrustPulse plugins. All versions loading compromised JavaScript files from vendor infrastructure are affected.

PushEngage15 Jun · 07:59 UTC
Arch User Repository supply chain attack: 400+ packages backdooredcriticalbug_reportVulnerability
bug_reportVulnerability

Arch User Repository supply chain attack: 400+ packages backdoored

Arch Linux users who installed or updated packages from the Arch User Repository (AUR) during the compromise window. Over 400 AUR packages contained malicious build scripts deploying a Rust-based infostealer.

Arch Linux12 Jun · 17:33 UTC
400+ Arch User Repository packages compromised with rootkit and infostealercriticalbug_reportVulnerability
bug_reportVulnerability

400+ Arch User Repository packages compromised with rootkit and infostealer

Arch Linux users who installed or updated packages from the Arch User Repository (AUR). Over 400 AUR packages confirmed compromised. Specific package names and versions not yet disclosed.

Arch Linux12 Jun · 15:03 UTC
npm v12 disables install scripts by default to block supply chain attackshighbug_reportVulnerability
bug_reportVulnerability

npm v12 disables install scripts by default to block supply chain attacks

npm version 12 and later. All Node.js projects using npm for package management. Breaking change affects packages that legitimately rely on install/postinstall lifecycle hooks.

GitHub11 Jun · 04:23 UTC
Miasma credential-stealing framework source code leaked on GitHubhighbug_reportVulnerability
bug_reportVulnerability

Miasma credential-stealing framework source code leaked on GitHub

Open-source software ecosystems and their supply chains. Organizations consuming packages from public repositories (npm, PyPI, RubyGems, etc.) are at increased risk. No specific vendor or product version affected; threat is ecosystem-wide.

BleepingComputer10 Jun · 18:27 UTC
Microsoft GitHub repos compromised, 73 disabled for distributing malwarehighbug_reportVulnerability
bug_reportVulnerability

Microsoft GitHub repos compromised, 73 disabled for distributing malware

73 repositories across Microsoft's official GitHub organizations (Azure, microsoft, Azure-Samples, MicrosoftDocs). Organizations using Microsoft sample code, Azure templates, or CI/CD pipelines referencing these repositories are potentially affected.

Microsoft9 Jun · 13:42 UTC
PyPI supply chain attack: 19 packages with auto-executing credential stealerhighbug_reportVulnerability
bug_reportVulnerability

PyPI supply chain attack: 19 packages with auto-executing credential stealer

PyPI repository: 19 compromised packages containing 37 malicious wheel artifacts. Affects Python developers who installed these packages. Attack uses .pth files for automatic execution during pip install, targeting credential theft via Bun-based stea…

PyPI9 Jun · 07:13 UTC
PyPI supply-chain attack: 19 science packages compromised with malwarehighbug_reportVulnerability
bug_reportVulnerability

PyPI supply-chain attack: 19 science packages compromised with malware

19 science-focused Python packages on PyPI, collectively downloaded hundreds of thousands of times. Specific package names and versions not disclosed in summary. Affects Python developers using PyPI packages in scientific/research workflows.

BleepingComputer8 Jun · 18:41 UTC
Miasma worm compromises 73 Microsoft GitHub repos in supply chain attackhighbug_reportVulnerability
bug_reportVulnerability

Miasma worm compromises 73 Microsoft GitHub repos in supply chain attack

73 Microsoft GitHub repositories across four organizations: Azure, Azure-Samples, Microsoft, and MicrosoftDocs. GitHub has disabled access to affected repositories.

Microsoft6 Jun · 04:58 UTC
Toshiba, Muji sites show credential-stealing prompts via polyfill supply chainhighbug_reportVulnerability
bug_reportVulnerability

Toshiba, Muji sites show credential-stealing prompts via polyfill supply chain

Toshiba and Muji public websites, potentially other sites using the compromised third-party polyfill library. Scope of affected sites and specific polyfill service not yet confirmed.

Toshiba5 Jun · 19:54 UTC
npm supply chain attack: 50+ packages deliver IronWorm stealer and rootkitcriticalbug_reportVulnerability
bug_reportVulnerability

npm supply chain attack: 50+ packages deliver IronWorm stealer and rootkit

npm ecosystem: over 50 compromised legitimate packages. Affects developers using npm for JavaScript/Node.js projects. IronWorm targets developer credentials and source code with eBPF kernel-level persistence.

npm5 Jun · 16:05 UTC
Red Hat npm packages compromised with Miasma credential stealerhighbug_reportVulnerability
bug_reportVulnerability

Red Hat npm packages compromised with Miasma credential stealer

Over 30 npm packages in the '@redhat-cloud-services' namespace on npm registry. Affects developers and CI/CD pipelines consuming these packages. Specific package names and versions not yet disclosed.

Red Hat1 Jun · 19:38 UTC
Miasma supply chain attack compromises Red Hat npm packagescriticalbug_reportVulnerability
bug_reportVulnerability

Miasma supply chain attack compromises Red Hat npm packages

Red Hat Cloud Services npm packages (@redhat-cloud-services scope). Affects developers and CI/CD pipelines using these packages. Scope includes any environment where compromised packages were installed.

Red Hat1 Jun · 15:40 UTC
Malicious npm package codexui-android steals OpenAI tokens, 29K downloadshighbug_reportVulnerability
bug_reportVulnerability

Malicious npm package codexui-android steals OpenAI tokens, 29K downloads

npm package codexui-android (all versions). Targets developers using OpenAI Codex APIs. Affects organizations with Node.js/npm development environments where this package was installed.

OpenAI1 Jun · 07:31 UTC
33 malicious npm packages deployed in dependency confusion recon campaignhighbug_reportVulnerability
bug_reportVulnerability

33 malicious npm packages deployed in dependency confusion recon campaign

npm ecosystem; organizations using private npm packages with names vulnerable to dependency confusion attacks. Affects developer workstations, CI/CD pipelines, and build environments that may inadvertently install public packages instead of intended…

npm29 May · 22:06 UTC
Malicious NuGet package "Sicoob.Sdk" steals banking credentialshighbug_reportVulnerability
bug_reportVulnerability

Malicious NuGet package "Sicoob.Sdk" steals banking credentials

NuGet package "Sicoob.Sdk" versions 2.0.0 through 2.0.4. Targets developers integrating with Sicoob (Brazilian cooperative banking system). Affects .NET development environments where the malicious package was installed.

Sicoob29 May · 07:11 UTC
Malicious npm package targets Claude AI user data directoryhighbug_reportVulnerability
bug_reportVulnerability

Malicious npm package targets Claude AI user data directory

npm package "mouse5212-super-formatter" (all versions). Targets developers using Anthropic Claude AI tools with access to /mnt/user-data directory. Affects Node.js development environments where the malicious package was installed.

npm27 May · 13:44 UTC
Glassworm botnet targeting developers disrupted via C2 takedownhighbug_reportVulnerability
bug_reportVulnerability

Glassworm botnet targeting developers disrupted via C2 takedown

Software developers and development environments targeted by Glassworm botnet. The botnet leveraged Solana blockchain and BitTorrent DHT for command-and-control infrastructure, indicating attacks against software supply chains.

BleepingComputer27 May · 11:28 UTC
CrowdStrike, Google disrupt GlassWorm C2 targeting software developershighbug_reportVulnerability
bug_reportVulnerability

CrowdStrike, Google disrupt GlassWorm C2 targeting software developers

Software developers using third-party packages and browser extensions. GlassWorm campaign active since early 2025, distributing malware through supply chain vectors including malicious packages and extensions.

CrowdStrike27 May · 09:48 UTC
TrapDoor campaign deploys credential stealers across npm, PyPI, Crates.iocriticalbug_reportVulnerability
bug_reportVulnerability

TrapDoor campaign deploys credential stealers across npm, PyPI, Crates.io

34+ malicious packages (384+ versions) distributed across npm (Node.js), PyPI (Python), and Crates.io (Rust) repositories. Campaign active since May 2026. Affects developers and CI/CD pipelines consuming packages from these ecosystems.

npm25 May · 03:59 UTC
Laravel Lang packages compromised to deliver credential-stealing malwarehighbug_reportVulnerability
bug_reportVulnerability

Laravel Lang packages compromised to deliver credential-stealing malware

Laravel Lang localization packages distributed via Composer. Affects developers who installed or updated compromised packages during the attack window. Specific package names and versions not yet publicly disclosed.

Laravel23 May · 18:48 UTC
Supply chain attack compromises 8 Packagist packages with malicious binaryhighbug_reportVulnerability
bug_reportVulnerability

Supply chain attack compromises 8 Packagist packages with malicious binary

Eight Composer packages on Packagist containing JavaScript components. Malicious code injected into package.json files executes a Linux binary from GitHub Releases. Downstream projects using these packages are affected.

Packagist23 May · 14:07 UTC
Laravel-Lang packages compromised to deliver credential-stealing malwarehighbug_reportVulnerability
bug_reportVulnerability

Laravel-Lang packages compromised to deliver credential-stealing malware

Multiple Laravel-Lang PHP packages compromised: laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, and laravel-lang/actions. Affects Laravel PHP applications using these localization packages.

Laravel-Lang23 May · 07:51 UTC
Compromised @antv npm packages deploy credential-stealing malwarecriticalbug_reportVulnerability
bug_reportVulnerability

Compromised @antv npm packages deploy credential-stealing malware

Multiple @antv npm packages compromised with Mini Shai-Hulud malware. Affects Linux-based CI/CD pipelines using npm install. Targets credentials from GitHub, AWS, Kubernetes, HashiCorp Vault, npm, and 1Password.

npm20 May · 15:48 UTC
Grafana breach via unrotated GitHub token after TanStack npm compromisehighbug_reportVulnerability
bug_reportVulnerability

Grafana breach via unrotated GitHub token after TanStack npm compromise

Grafana Labs infrastructure. Organizations using Grafana products are not directly affected by the breach itself, but should monitor for potential secondary impacts.

Grafana20 May · 13:46 UTC
Over 600 malicious npm packages published in Shai-Hulud campaignhighbug_reportVulnerability
bug_reportVulnerability

Over 600 malicious npm packages published in Shai-Hulud campaign

npm ecosystem: 600+ malicious packages published by threat actors. Affects organizations using npm for JavaScript/Node.js dependency management. Specific package names not provided in summary.

npm19 May · 12:30 UTC