Tag: Supply Chain Attacks

npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks
News

npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks

In an effort to strengthen the security of the software supply chain, GitHub has implemented new controls for npm that allow maintainers to specifically authorize a release before the packages are made available for public installation. The capability, known as staged publishing, is currently widely accessible on npm. Before a package is published to npmjs[.]com, it requires a human maintainer to successfully complete a two-factor authentication (2FA) challenge. The prebuilt tarball is submitted to a stage queue where a maintainer must specifically approve it before it becomes installable, as opposed to a straight publication that instantly makes a package version available to users, according to GitHub. According to the Microsoft-owned company, the modification guarantees "proof...
Google’s Android Apps Get Public Verification to Stop Supply Chain Attacks
News

Google’s Android Apps Get Public Verification to Stop Supply Chain Attacks

To protect the ecosystem from supply chain assaults, Google has announced increased Binary Transparency for Android. According to Google's product and security teams, this new public ledger guarantees that the Google apps on your device are precisely what we meant to create and distribute. The program expands on Google's October 2021 launch of Pixel Binary Transparency, which ensures that Pixel devices are only running verified operating system (OS) software by maintaining a public, cryptographic log that contains metadata about official factory images. Certificate Transparency, an open architecture that mandates that all issued SSL/TLS certificates be documented in public, append-only, cryptographically verifiable logs to aid in the detection of fraudulent or incorrectly issued ...
AWS CodeBuild Misconfiguration Exposed GitHub Repos to Potential Supply Chain Attacks
News

AWS CodeBuild Misconfiguration Exposed GitHub Repos to Potential Supply Chain Attacks

The cloud service provider's GitHub repositories, including its AWS JavaScript SDK, might have been completely taken over due to a serious misconfiguration in Amazon Web Services (AWS) CodeBuild, endangering all AWS environments. Cloud security firm Wiz has dubbed the vulnerability CodeBreach. After responsible disclosure on August 25, 2025, AWS resolved the problem in September 2025. Researchers Yuval Avrahami and Nir Ohfeld stated in a report shared with The Hacker News that by taking advantage of CodeBreach, attackers could have introduced malicious code to initiate a platform-wide compromise, potentially affecting not only the innumerable apps that rely on the SDK but also the Console itself, endangering every AWS account. According to Wiz, the vulnerability in the continuous...
Malicious PyPI and npm Packages Discovered Exploiting Dependencies in Supply Chain Attacks
News

Malicious PyPI and npm Packages Discovered Exploiting Dependencies in Supply Chain Attacks

A malicious package that adds malicious behavior through a dependency that enables it to establish persistence and accomplish code execution has been found by cybersecurity experts in the Python Package Index (PyPI) repository. According to Zscaler ThreatLabz, the program, dubbed termncolor, uses a multi-stage malware operation to actualize its malicious capability through a dependent package called colorinal. Colorinal received 529 downloads, compared to 355 for termncolor. On PyPI, both libraries are no longer accessible. According to researchers Manisha Ramcharan Prajapati and Satyam Singh, this attack may use DLL side-loading to enable decryption, create persistence, and carry out command-and-control (C2) communication, ultimately leading to remote code execution. Following i...
Critical Open VSX Registry Flaw Exposes Millions of Developers to Supply Chain Attacks
News

Critical Open VSX Registry Flaw Exposes Millions of Developers to Supply Chain Attacks

A serious supply chain risk has been identified by cybersecurity researchers due to a key vulnerability in the Open VSX Registry ("open-vsx[.]org") that, if successfully exploited, might have allowed attackers to take over the whole Visual Studio Code extensions marketplace. According to researcher Oren Yomtov of Koi Security, this flaw gives attackers complete access over the marketplace for extensions, which in turn gives them complete control over millions of developer computers. A hostile actor could release harmful updates to all Open VSX extensions by taking advantage of a CI flaw. The maintainers recommended several iterations of changes after responsible disclosure on May 4, 2025, and a final patch was released on June 25. An open-source project that serves as a substitut...
Supply Chain Attacks Can Exploit Entry Points in Python, npm, and Open-Source Ecosystems
News

Supply Chain Attacks Can Exploit Entry Points in Python, npm, and Open-Source Ecosystems

Researchers studying cybersecurity have discovered that software supply chain assaults can be staged by abusing entry points in a variety of programming ecosystems, including PyPI, npm, Ruby Gems, NuGet, Dart Pub, and Rust Crates. There is a significant risk in the open-source community since attackers can use these entry points to launch malicious code when particular commands are executed, according to a paper released by Checkmarx researchers Yehuda Gelb and Elad Rapaport and shared with The Hacker News. Entry-point attacks provide threat actors with a more cunning and persistent way to compromise systems that can get past conventional security measures, according to the software supply chain security business read more about Supply Chain Attacks Can Exploit Entry Points in Pytho...
Critical Flaws in CocoaPods Expose iOS and macOS Apps to Supply Chain Attacks
News

Critical Flaws in CocoaPods Expose iOS and macOS Apps to Supply Chain Attacks

Three security vulnerabilities have been found in the CocoaPods dependency management for the Objective-C and Swift Cocoa projects. These vulnerabilities might be used to stage software supply chain assaults, which would pose a serious danger to downstream customers. Researchers Reef Spektor and Eran Vaknin of E.V.A Information Security stated in a paper released today that the vulnerabilities enable "any malicious actor to claim ownership over thousands of unclaimed pods and insert malicious code into many of the most popular iOS and macOS applications." The three vulnerabilities have reportedly been fixed by CocoaPods as of October 2023, according to the Israeli application security company. In reaction to the disclosures, it also resets all user sessions at that particular time r...
Hackers Hijack GitHub Accounts in Supply Chain Attack Affecting Top-gg and Others
News

Hackers Hijack GitHub Accounts in Supply Chain Attack Affecting Top-gg and Others

An advanced campaign of cyberattacks, masterminded by anonymous enemies, has affected multiple developers and the GitHub organization account linked to Top.gg, a Discord bot discovery platform. According to a technical report provided by Checkmarx to The Hacker News, "the threat actors used multiple TTPs in this attack, including account takeover via stolen browser cookies, contributing malicious code with verified commits, setting up a custom Python mirror, and publishing malicious packages to the PyPI registry." It is claimed that sensitive data, including passwords, credentials, and other important information, was stolen as a result of the software supply chain attack read more Hackers Hijack GitHub Accounts in Supply Chain Attack Affecting Top-gg and Others. Get up to date o...
Chinese State Hackers Target Tibetans with Supply Chain and Watering Hole Attacks
News

Chinese State Hackers Target Tibetans with Supply Chain and Watering Hole Attacks

At least since September 2023, the threat actor with ties to China known as Evasive Panda has been planning supply chain and watering hole assaults on Tibetan users. Delivering malicious downloaders for Windows and macOS that activate a known backdoor named MgBot and a previously unrecognized Windows implant called Nightdoor is the last step in the attack. The results are based on research by ESET, which claims that the attackers gained access to at least three websites in order to conduct supply-chain compromises of Tibetan software companies and watering-hole attacks. January 2024 marked the discovery of the operation. Evasive Panda, also known as Bronze Highland and Daggerfly, has been in operation since 2012. The Slovak cybersecurity company first revealed in April 2023 that ...
New Hugging Face Vulnerability Exposes AI Models to Supply Chain Attacks
News

New Hugging Face Vulnerability Exposes AI Models to Supply Chain Attacks

Researchers studying cybersecurity have discovered that it is feasible to breach the Hugging Face Safetensors conversion service, which might lead to supply chain attacks and the eventual theft of user-submitted models. According to a research released by HiddenLayer last week, it is possible to submit malicious pull requests containing data controlled by the attacker from the Hugging Face service to any repository on the platform. Additionally, any models submitted through the conversion service can be hijacked. Malicious actors can thus request changes to any repository on the platform by posing as the conversion bot, all thanks to a hijacked model that is intended to be converted by the service read more New Hugging Face Vulnerability Exposes AI Models to Supply Chain Attacks. ...