Supply Chain Security Laravel-Lang Packages Poisoned for Malware Delivery Published within a 15-minute window, the malicious tags introduced backdoors to exfiltrate CI secrets. Ionut ArghireMay 25, 2026
Application Security Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack Fake automated commits injected GitHub Actions workflows containing payloads to steal credentials, CI secrets, keys, and tokens. Ionut ArghireMay 25, 2026
Data Breaches Grafana Says Codebase and Other Data Stolen via TanStack Supply Chain Attack Hackers accessed Grafana’s GitHub repositories after a token compromised in the TanStack attack was not rotated. Ionut ArghireMay 22, 2026
Malware & Threats Over 320 NPM Packages Hit by Fresh Mini Shai-Hulud Supply Chain Attack A compromised maintainer account was used to publish malicious package versions across the @antv namespace. Ionut ArghireMay 20, 2026
Artificial Intelligence OpenAI Hit by TanStack Supply Chain Attack Two employee devices were compromised in the attack, and credential material was stolen from OpenAI code repositories. Ionut ArghireMay 15, 2026
Malware & Threats TanStack, Mistral AI, UiPath Hit in Fresh Supply Chain Attack Over 400 malicious versions of 170 packages were published as part of the new Mini Shai-Hulud campaign. Ionut ArghireMay 12, 2026
Supply Chain Security Checkmarx Jenkins AST Plugin Compromised in Supply Chain Attack A malicious version of the plugin was published to the Jenkins Marketplace late last week. Ionut ArghireMay 11, 2026
Malware & Threats Vendor Says Daemon Tools Supply Chain Attack Contained The software developer has identified the impacted systems, removed potentially compromised files, and validated installation packages. Ionut ArghireMay 7, 2026
Malware & Threats Government, Scientific Entities Hit via Daemon Tools Supply Chain Attack While trojanized Daemon Tools versions were installed worldwide, a sophisticated backdoor was dropped only on a dozen systems. Ionut ArghireMay 6, 2026
Supply Chain Security 1,800 Hit in Mini Shai-Hulud Attack on SAP, Lightning, Intercom The compromised Lightning and Intercom packages have a combined monthly download count of nearly 10 million. Ionut ArghireMay 1, 2026
Malware & Threats SAP NPM Packages Targeted in Supply Chain Attack The Mini Shai-Hulud attack introduced a preinstall hook to fetch and execute a Bun binary and bypass security monitoring. Ionut ArghireApril 30, 2026
Artificial Intelligence Critical Gemini CLI Flaw Enabled Host Code Execution, Supply Chain Attacks An attacker could have planted a malicious configuration to execute commands outside the sandbox. Eduard KovacsApril 30, 2026
Data Breaches Checkmarx Confirms Data Stolen in Supply Chain Attack The hackers exfiltrated the data from Checkmarx’s GitHub environment on March 30, a week after publishing malicious code. Ionut ArghireApril 29, 2026
Supply Chain Security Bitwarden NPM Package Hit in Supply Chain Attack Tied to a fresh Checkmarx supply chain attack claimed by TeamPCP, the incident references the Shai-Hulud worm. Ionut ArghireApril 24, 2026
Artificial Intelligence OpenAI Impacted by North Korea-Linked Axios Supply Chain Hack The AI giant is taking action after determining that a macOS code signing certificate may have been compromised. Eduard KovacsApril 13, 2026
Malware & Threats CPUID Hacked to Serve Trojanized CPU-Z and HWMonitor Downloads Download links were replaced by a Russian-speaking threat actor to distribute a recently emerged malware named STX RAT. Eduard KovacsApril 13, 2026
Malware & Threats Guardarian Users Targeted With Malicious Strapi NPM Packages Hackers published 36 NPM packages posing as Strapi plugins to execute shells, escape containers, and harvest credentials. Ionut ArghireApril 6, 2026
Supply Chain Security North Korean Hackers Target High-Profile Node.js Maintainers The threat actor behind the Axios supply chain attack has been aiming at other maintainers in its social engineering campaign. Ionut ArghireApril 6, 2026
Data Breaches European Commission Confirms Data Breach Linked to Trivy Supply Chain Attack Hackers stole over 300GB of data from the Commission’s AWS environment, including personal information. Ionut ArghireApril 4, 2026
Supply Chain Security Mercor Hit by LiteLLM Supply Chain Attack The AI recruiting firm is investigating the incident as Lapsus$ claimed the theft of 4TB of Mercor data. Ionut ArghireApril 2, 2026