7 stories tagged #supply-chain attack

  1. TrapDoor Attack Targets Solana, Sui, and Aptos Wallet Data via Fake Packages
    crypto

    TrapDoor Attack Targets Solana, Sui, and Aptos Wallet Data via Fake Packages

    Security firm Socket uncovers supply-chain attack with 34+ malicious packages targeting crypto and AI developers.

    5d ago 1 min read
  2. GitHub Breached: 3,800 Internal Repos Stolen via Poisoned VS Code Extension
    tech

    GitHub Breached: 3,800 Internal Repos Stolen via Poisoned VS Code Extension

    TeamPCP compromised GitHub via a malicious VS Code extension, stealing source code for Actions, Copilot, and CodeQL, now sold for $50,000.

    last wk. 1 min read
  3. GitHub Probes Data Breach After Employee Device Hijacked via Malicious VS Code Extension
    tech

    GitHub Probes Data Breach After Employee Device Hijacked via Malicious VS Code Extension

    GitHub investigates unauthorized access to internal repositories after an employee device was compromised. Hacker group TeamPCP claims to have stolen 4,000 private repos.

    2w ago 1 min read
  4. Cyber Attack Targets Daemon Tools: Backdoor Threatens 100 Organizations Globally
    tech

    Cyber Attack Targets Daemon Tools: Backdoor Threatens 100 Organizations Globally

    Hackers backdoored the popular Daemon Tools disk app in a monthlong supply-chain attack, infecting 100 entities across multiple continents.

    last mo. 1 min read
  5. Open Source Package Compromised, Steals User Credentials
    tech

    Open Source Package Compromised, Steals User Credentials

    A popular open-source package with over one million monthly downloads has been found to steal user credentials. Developers urge immediate action.

    last mo. 1 min read
  6. Chinese Hacker Group Wuhan Anshun Stole $7M via Crypto Wallet Supply-Chain Attacks
    crypto

    Chinese Hacker Group Wuhan Anshun Stole $7M via Crypto Wallet Supply-Chain Attacks

    A China-based collective posing as Wuhan Anshun Technology infiltrated crypto wallets using malicious browser extensions and compromised Electron apps-stealing $7M across Ethereum, BNB Chain, and Arbitrum.

    2mo ago 1 min read
  7. Invisible Code Threatens GitHub and Software Repositories
    tech

    Invisible Code Threatens GitHub and Software Repositories

    Hackers exploit hidden Unicode characters to conceal malicious payloads in software supply chains, bypassing AI and human review.

    2mo ago 1 min read