A growing class of supply-chain tricks targets the moment an AI assistant turns a made-up package, repo, or domain name into an actual fetch or install action.
A campaign involving compromised GitHub repositories and tainted Packagist releases shows how software delivery systems can be turned against cPanel and WHM operators.
A reported package-publishing compromise in the AsyncAPI ecosystem shows how GitHub Actions, npm trust, and generator tooling can become a malware delivery path when release controls are subverted.
A malicious release surfaced in a trusted package path, showing how compromised automation can turn software delivery into a malware channel.
A reported abuse of ViPNet's update mechanism shows how a normal maintenance channel can turn into a high-value target when trust is the thing under attack.
Four AsyncAPI packages were reportedly republished with malicious releases described as a RAT-focused Miasma build, while automatic propagation was disabled.
Multiple npm package versions tied to Jscrambler were poisoned in a supply chain attack, showing how a trusted update path can become the delivery mechanism for credential-stealing malware.
A malicious jscrambler release in npm shows how one compromised publish path can put developer workstations and CI jobs in the crosshairs of cloud and source-control secrets.
A multi-stage Trojan tied to Visual Studio project files shows how ordinary build logic can turn into a supply-chain attack surface.
Researchers demonstrated a naming attack against AI assistants that can move from hallucinated lookups to remote code execution and, in some cases, malware delivery.
A lookalike NuGet package built to imitate Braintree's .NET client shows how one deceptive dependency can put card data and gateway secrets in reach of an application.
Researchers reported a NuGet package named Braintree.Net that mimics a payment SDK and is said to steal card data only in live environments, a reminder that build-time trust can become runtime risk.
PolinRider shows how a software supply-chain operation can turn legitimate open source assets into a route for backdoors and credential theft, putting developer workstations at the center of the blast radius.
A campaign tied to PolinRider has put malicious packages and browser extensions into npm, Packagist, Go, and Google Chrome, showing how one delivery pattern can travel across very different trust systems.
A supply-chain campaign tied to PolinRider shows how package ecosystems can turn routine development work into a high-risk execution path.
A law-enforcement FLASH alert tied to TeamPCP points to a familiar trick with dangerous reach: tampering with trusted software paths to harvest cloud tokens, SSH keys, and Kubernetes secrets.
A malicious package campaign tied to Telegram bot development shows how a trusted Python repository can become the delivery layer for server-side compromise.
Decades-old Bash tricks are being used to test whether open-source AI coding agents can be pushed past their safety checks and into dangerous repository-driven workflows.
A package-chain compromise can do more than slip in bad code - it can turn developer tooling itself into the execution path for a cross-platform Python infostealer.
The latest Miasma-linked supply-chain activity shows how a single poisoned release can pressure multiple trust layers at once, from package registries to build automation.