Tag Archives: Supply chain security
Supply-Chain Attack: Massive Megalodon Campaign Hits 5,500+ GitHub Repositories
A sophisticated supply-chain attack dubbed Megalodon has compromised over 5,500 GitHub repositories by injecting malicious CI/CD workflows and harvesting sensitive deployment credentials. Continue reading
GitHub Codebase Breach: Internal Repositories Stolen via VS Code Extension
Microsoft’s GitHub is investigating a major GitHub codebase breach after hackers exfiltrated thousands of internal repositories using a poisoned VS Code extension. Continue reading
GemStuffer RubyGems Campaign: Weaponizing Registries for Data Storage
The GemStuffer RubyGems campaign has revealed a mysterious new tactic where threat actors utilize official package registries as covert storage layers for scraped public data. Continue reading
Supply Chain Attack: Checkmarx Confirms Massive Credential Exfiltration
A devastating supply chain attack targeting the KICS project has led to the exfiltration of sensitive API keys and database credentials for MongoDB and MySQL. Continue reading
AI-Enhanced npm Malware: North Korea’s Operation Masquerade Hits SAP
North Korean state-sponsored actors have launched Operation Masquerade, using AI-enhanced npm malware to infiltrate enterprise software supply chains and steal credentials. Continue reading
Axios Backdoor: Lead Maintainer Compromised via Social Engineering
A critical Axios backdoor has been identified after a lead maintainer fell victim to social engineering, enabling a massive supply chain compromise. Continue reading
Bitwarden CLI Compromise: Supply Chain Attack and Remediation Steps
A major Bitwarden CLI compromise was identified in April 2026 involving a malicious npm package that harvests SSH keys and tokens, requiring immediate secret rotation for affected developers. Continue reading
Checkmarx Supply Chain Attack: Malicious KICS Images and VS Code Extensions
A sophisticated Checkmarx supply chain attack has been identified, involving poisoned KICS Docker images and malicious VS Code extensions designed to exfiltrate sensitive credentials and developer tokens. Continue reading
Axios Supply Chain Compromise: CISA Issues Emergency Alert
CISA has issued an emergency alert regarding the Axios supply chain compromise, where malicious code in the popular NPM package delivers a Remote Access Trojan to developer environments and CI/CD pipelines. Continue reading