Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-20 · 02:03 UTC
articleTotal: 593 reports

Filtered Reports

30 / 50 results
Active filter:tag: #supply-chain✕ clear
Seven malicious npm packages target Vite ecosystem with blockchain C2 RAThighbug_reportVulnerability
bug_reportVulnerability

Seven malicious npm packages target Vite ecosystem with blockchain C2 RAT

npm package ecosystem, specifically projects using Vite frontend tooling. Seven malicious packages identified in the ViteVenom campaign. Any JavaScript/Node.js development environments that installed these packages are compromised.

npm16:54 UTC
DigiCert breach linked to Chinese APT; code-signing certs stolencriticalbug_reportVulnerability
bug_reportVulnerability

DigiCert breach linked to Chinese APT; code-signing certs stolen

DigiCert certificate authority infrastructure compromised in April 2026. Code-signing certificates stolen by CylindricalCanine (GoldenEyeDog/APT-Q-27 subgroup).

DigiCert14:39 UTC
Malicious npm and PyPI packages impersonate Paysafe payment SDKshighbug_reportVulnerability
bug_reportVulnerability

Malicious npm and PyPI packages impersonate Paysafe payment SDKs

Developers using npm and PyPI repositories who may have installed counterfeit packages impersonating Paysafe, Skrill, and Neteller payment SDKs. Affects development environments and potentially downstream applications integrating these malicious pack…

Paysafe17:54 UTC
North Korean actors deploy 108 malicious packages in PolinRider campaignhighbug_reportVulnerability
bug_reportVulnerability

North Korean actors deploy 108 malicious packages in PolinRider campaign

npm, Packagist (PHP), Go modules, and Google Chrome Web Store. 108 malicious packages and extensions published. Maintainer accounts actively compromised. Campaign linked to North Korean Contagious Interview threat group.

The Hacker News09:17 UTC
North Korean actors deploy malicious npm packages to steal developer secretshighbug_reportVulnerability
bug_reportVulnerability

North Korean actors deploy malicious npm packages to steal developer secrets

npm ecosystem: malicious packages "rollup-packages-polyfill-core" and "rollup-runtime-polyfill-core" impersonating legitimate "rollup-plugin-polyfill-node".

npm14:07 UTC
LLM hallucinations exploited for supply chain attacks via phantom domainshighbug_reportVulnerability
bug_reportVulnerability

LLM hallucinations exploited for supply chain attacks via phantom domains

Organizations using LLMs for development assistance, code generation, or package recommendations. Developers relying on AI-generated domain/package suggestions without verification.

Unit 42 (Palo Alto)23:00 UTC
Trojanized Pyrogram forks on PyPI target Telegram bot developershighbug_reportVulnerability
bug_reportVulnerability

Trojanized Pyrogram forks on PyPI target Telegram bot developers

Python developers using PyPI packages for Telegram bot development. Malicious forks of Pyrogram library active since November 2024. Affects developers who may have installed compromised packages instead of legitimate Pyrogram.

PyPI19:02 UTC
Hijacked npm and Go packages deploy cross-platform stealer via VS Codehighbug_reportVulnerability
bug_reportVulnerability

Hijacked npm and Go packages deploy cross-platform stealer via VS Code

Compromised npm and Go packages targeting developers using Microsoft Visual Studio Code on Windows, Linux, and macOS. Attack bypasses npm v12 lifecycle script protections by abusing VS Code task execution.

npm03:36 UTC
Agentic coding tools vulnerable to hidden malicious payloads in reposhighbug_reportVulnerability
bug_reportVulnerability

Agentic coding tools vulnerable to hidden malicious payloads in repos

Agentic coding tools and AI-assisted development platforms that automatically fetch and execute code from GitHub repositories. Specific products not disclosed.

BleepingComputer12:22 UTC
Polymarket frontend compromised via third-party vendor; $3M stolenhighbug_reportVulnerability
bug_reportVulnerability

Polymarket frontend compromised via third-party vendor; $3M stolen

Polymarket platform users. Attack vector: malicious JavaScript injected into frontend via compromised third-party vendor. Approximately $3 million in customer funds stolen. No CVE assigned.

Polymarket16:04 UTC
Miasma malware compromises npm packages LeoPlatform and RStreamshighbug_reportVulnerability
bug_reportVulnerability

Miasma malware compromises npm packages LeoPlatform and RStreams

npm packages LeoPlatform and RStreams compromised by Miasma malware family. Attack extends to GitHub Actions workflows and Go ecosystem. Organizations using these packages or dependent projects are affected.

npm09:05 UTC
CI/CD flaw "Cordyceps" exposes 300+ GitHub repos to supply-chain takeovercriticalbug_reportVulnerability
bug_reportVulnerability

CI/CD flaw "Cordyceps" exposes 300+ GitHub repos to supply-chain takeover

300+ GitHub repositories across major organizations including Microsoft, Google, and Apache. Vulnerability affects GitHub Actions CI/CD workflows. Specific products and versions not disclosed in available data.

Microsoft10:48 UTC
Malicious AI skills in ClawHub marketplace evade scanners, deploy infostealershighbug_reportVulnerability
bug_reportVulnerability

Malicious AI skills in ClawHub marketplace evade scanners, deploy infostealers

ClawHub marketplace users consuming third-party AI skills. Specific affected products: OpenClaw and ClawHub platforms. Scope includes organizations deploying AI agents with marketplace-sourced skills that may contain evasive malware delivering infost…

OpenClaw, ClawHub20:00 UTC
GitHub blocks pwn request attacks in actions/checkout starting June 2026highbug_reportVulnerability
bug_reportVulnerability

GitHub blocks pwn request attacks in actions/checkout starting June 2026

GitHub Actions workflows using actions/checkout with pull_request_target trigger. Organizations using GitHub Actions for CI/CD pipelines are affected. The security update applies to all repositories using the actions/checkout action after June 18, 20…

GitHub12:22 UTC
LastPass breached via Klue supply chain attack; OAuth tokens stolenhighbug_reportVulnerability
bug_reportVulnerability

LastPass breached via Klue supply chain attack; OAuth tokens stolen

LastPass customers. Attack vector: compromised Klue third-party service leading to OAuth token theft and unauthorized access to LastPass Salesforce environment containing customer data.

LastPass11:58 UTC
Malicious npm packages deliver Windows RAT to JavaScript developershighbug_reportVulnerability
bug_reportVulnerability

Malicious npm packages deliver Windows RAT to JavaScript developers

Three npm packages (aes-decode-runner-pro, postcss-minify-selector, postcss-minify-selector-parser) published within the past month. Total downloads: 145-615 per package. Affects Windows-based development environments using npm package manager.

npm06:54 UTC
ShapedPlugin WordPress Pro plugins backdoored via compromised update channelhighbug_reportVulnerability
bug_reportVulnerability

ShapedPlugin WordPress Pro plugins backdoored via compromised update channel

Multiple ShapedPlugin Pro WordPress plugins distributed through official licensed update channels. Exact plugin names and affected versions not specified.

ShapedPlugin16:00 UTC
North Korean APT compromised 140+ npm packages via Mastra AI frameworkhighbug_reportVulnerability
bug_reportVulnerability

North Korean APT compromised 140+ npm packages via Mastra AI framework

Mastra AI framework and over 140 dependent npm packages. Organizations using Mastra AI or downstream dependencies in Node.js/JavaScript applications are affected.

Mastra AI12:09 UTC
Salesforce disables Klue integration after OAuth token abuse exposes datahighbug_reportVulnerability
bug_reportVulnerability

Salesforce disables Klue integration after OAuth token abuse exposes data

Salesforce customers using the Klue Battlecards app integration. OAuth tokens were abused to access customer data. Integration disabled as of June 11, 2026.

Salesforce07:03 UTC
ShapedPlugin WordPress plugins compromised in supply chain attackhighbug_reportVulnerability
bug_reportVulnerability

ShapedPlugin WordPress plugins compromised in supply chain attack

Multiple WordPress plugins from ShapedPlugin vendor. Infected releases distributed to paying customers via official update mechanism. Specific plugin names and version numbers not disclosed in provided data.

ShapedPlugin10:55 UTC
Poisoned npm package compromises 140+ projects via postinstall payloadhighbug_reportVulnerability
bug_reportVulnerability

Poisoned npm package compromises 140+ projects via postinstall payload

140+ projects using a malicious npm package containing a hidden postinstall script. Affects Node.js/JavaScript development environments consuming npm dependencies. Specific package name not disclosed in summary.

npm01:43 UTC
Supply chain attack compromises 144 Mastra npm packages via hijacked accountcriticalbug_reportVulnerability
bug_reportVulnerability

Supply chain attack compromises 144 Mastra npm packages via hijacked account

144 npm packages in the @mastra/* namespace (Mastra AI framework for JavaScript/TypeScript). Attack vector: compromised npm contributor account (ehindero). All downstream projects using affected Mastra packages are potentially impacted.

Mastra05:38 UTC
Malicious JetBrains IDE plugins steal AI API keys from developershighbug_reportVulnerability
bug_reportVulnerability

Malicious JetBrains IDE plugins steal AI API keys from developers

JetBrains Marketplace users who installed any of the 15+ malicious plugins. Affects developers using JetBrains IDEs (IntelliJ IDEA, PyCharm, WebStorm, etc.) with AI API keys configured. Specific plugin names and versions not provided in summary.

JetBrains19:54 UTC
Awesome Motive CDN breach compromises WordPress plugins in supply-chain attackhighbug_reportVulnerability
bug_reportVulnerability

Awesome Motive CDN breach compromises WordPress plugins in supply-chain attack

WordPress plugins OptinMonster, TrustPulse, and PushEngage distributed via Awesome Motive's CDN. All versions served through the compromised CDN infrastructure are potentially affected.

Awesome Motive15:37 UTC
Supply chain attack hits PushEngage, OptinMonster, TrustPulse pluginscriticalbug_reportVulnerability
bug_reportVulnerability

Supply chain attack hits PushEngage, OptinMonster, TrustPulse plugins

WordPress sites using PushEngage, OptinMonster, and TrustPulse plugins. All versions loading compromised JavaScript files from vendor infrastructure are affected.

PushEngage07:59 UTC
Arch User Repository supply chain attack: 400+ packages backdooredcriticalbug_reportVulnerability
bug_reportVulnerability

Arch User Repository supply chain attack: 400+ packages backdoored

Arch Linux users who installed or updated packages from the Arch User Repository (AUR) during the compromise window. Over 400 AUR packages contained malicious build scripts deploying a Rust-based infostealer.

Arch Linux17:33 UTC
400+ Arch User Repository packages compromised with rootkit and infostealercriticalbug_reportVulnerability
bug_reportVulnerability

400+ Arch User Repository packages compromised with rootkit and infostealer

Arch Linux users who installed or updated packages from the Arch User Repository (AUR). Over 400 AUR packages confirmed compromised. Specific package names and versions not yet disclosed.

Arch Linux15:03 UTC
npm v12 disables install scripts by default to block supply chain attackshighbug_reportVulnerability
bug_reportVulnerability

npm v12 disables install scripts by default to block supply chain attacks

npm version 12 and later. All Node.js projects using npm for package management. Breaking change affects packages that legitimately rely on install/postinstall lifecycle hooks.

GitHub04:23 UTC
Miasma credential-stealing framework source code leaked on GitHubhighbug_reportVulnerability
bug_reportVulnerability

Miasma credential-stealing framework source code leaked on GitHub

Open-source software ecosystems and their supply chains. Organizations consuming packages from public repositories (npm, PyPI, RubyGems, etc.) are at increased risk. No specific vendor or product version affected; threat is ecosystem-wide.

BleepingComputer18:27 UTC
Microsoft GitHub repos compromised, 73 disabled for distributing malwarehighbug_reportVulnerability
bug_reportVulnerability

Microsoft GitHub repos compromised, 73 disabled for distributing malware

73 repositories across Microsoft's official GitHub organizations (Azure, microsoft, Azure-Samples, MicrosoftDocs). Organizations using Microsoft sample code, Azure templates, or CI/CD pipelines referencing these repositories are potentially affected.

Microsoft13:42 UTC