Lunes 27 Julio 2026 01:03:34 GMT+02:00

Netcrook

InicioManifiesto
Noticias
Techcrook
Geocrook
WikicrookEquipoAppContactoLogin
EnglishItaliano

#Supply Chain Attack


When AI Invents the Dependency, Attackers May Own the Download

Published: 24 July 2026 18:34Category: Research, Exploits & Offensive SecurityAuthor: PATCHVIPER

A growing class of supply-chain tricks targets the moment an AI assistant turns a made-up package, repo, or domain name into an actual fetch or install action.

How a Trusted Build Pipeline Became a Launchpad for Server Attacks

Published: 23 July 2026 16:54Category: CybercrimeGeo: North America / USAAuthor: CRYSTALPROXY

A campaign involving compromised GitHub repositories and tainted Packagist releases shows how software delivery systems can be turned against cPanel and WHM operators.

When Release Automation Turns Hostile: The AsyncAPI npm Incident and the Trust Problem Behind It

Published: 21 July 2026 12:10Category: Malware & BotnetsAuthor: SIGNALMONK

A reported package-publishing compromise in the AsyncAPI ecosystem shows how GitHub Actions, npm trust, and generator tooling can become a malware delivery path when release controls are subverted.

When a Build Workflow Turns Hostile: The AsyncAPI npm Incident

Published: 21 July 2026 10:15Category: Malware & BotnetsAuthor: IRONQUERY

A malicious release surfaced in a trusted package path, showing how compromised automation can turn software delivery into a malware channel.

Trusted Updates, Untrusted Payloads: ViPNet Becomes the Delivery Path

Published: 19 July 2026 18:05Category: Cyber Warfare & Nation-State OperationsGeo: Europe / RussiaAuthor: AGONY

A reported abuse of ViPNet's update mechanism shows how a normal maintenance channel can turn into a high-value target when trust is the thing under attack.

When a Trusted npm Namespace Turns Into a Delivery Channel for Malware

Published: 14 July 2026 16:10Category: Malware & BotnetsAuthor: IRONQUERY

Four AsyncAPI packages were reportedly republished with malicious releases described as a RAT-focused Miasma build, while automatic propagation was disabled.

Poisoned Packages, Quiet Secrets: The Jscrambler npm Case Exposes a Familiar Trap

Published: 14 July 2026 12:20Category: Malware & BotnetsGeo: Europe / PortugalAuthor: IRONQUERY

Multiple npm package versions tied to Jscrambler were poisoned in a supply chain attack, showing how a trusted update path can become the delivery mechanism for credential-stealing malware.

Poisoned npm Update Turns a Security Tool Into a Secret Grabber

Published: 13 July 2026 10:35Category: Cloud, SaaS & Identity SecurityGeo: Europe / PortugalAuthor: SHADOWFIREWALL

A malicious jscrambler release in npm shows how one compromised publish path can put developer workstations and CI jobs in the crosshairs of cloud and source-control secrets.

When a Build File Becomes the Breach Door

Published: 11 July 2026 08:04Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A multi-stage Trojan tied to Visual Studio project files shows how ordinary build logic can turn into a supply-chain attack surface.

HalluSquatting Shows How AI Assistants Can Be Tricked Into Pulling the Wrong Code

Published: 10 July 2026 12:44Category: AI Security & Agentic SystemsAuthor: INTEGRITYFOX

Researchers demonstrated a naming attack against AI assistants that can move from hallucinated lookups to remote code execution and, in some cases, malware delivery.

The Fake SDK That Turns Payments Code Into a Theft Vector

Published: 10 July 2026 10:43Category: CybercrimeGeo: North America / USAAuthor: VULNCRUSADER

A lookalike NuGet package built to imitate Braintree's .NET client shows how one deceptive dependency can put card data and gateway secrets in reach of an application.

When a Payment Package Waits for Production, the Supply Chain Has Already Been Crossed

Published: 10 July 2026 10:40Category: CybercrimeGeo: North America / USAAuthor: CIPHERWARDEN

Researchers reported a NuGet package named Braintree.Net that mimics a payment SDK and is said to steal card data only in live environments, a reminder that build-time trust can become runtime risk.

When Trusted Repositories Become Delivery Chains for Malware

Published: 06 July 2026 18:55Category: Cyber Warfare & Nation-State OperationsGeo: Asia / North KoreaAuthor: AGONY

PolinRider shows how a software supply-chain operation can turn legitimate open source assets into a route for backdoors and credential theft, putting developer workstations at the center of the blast radius.

108 Poisoned Builds, One Shared Trap: The New Cross-Ecosystem Supply-Chain Wave

Published: 04 July 2026 14:07Category: Malware & BotnetsGeo: Asia / North KoreaAuthor: IRONQUERY

A campaign tied to PolinRider has put malicious packages and browser extensions into npm, Packagist, Go, and Google Chrome, showing how one delivery pattern can travel across very different trust systems.

When a Dependency Update Becomes the Doorway: PolinRider and the Open-Source Trust Trap

Published: 03 July 2026 10:42Category: Cyber Warfare & Nation-State OperationsGeo: Asia / North KoreaAuthor: AGONY

A supply-chain campaign tied to PolinRider shows how package ecosystems can turn routine development work into a high-risk execution path.

Trusted Updates, Stolen Identity: The New Supply-Chain Playbook for Cloud Intrusions

Published: 03 July 2026 10:17Category: Cyber Intelligence & Threat TrendsGeo: North America / USAAuthor: PHANTOMINTEGRITY

A law-enforcement FLASH alert tied to TeamPCP points to a familiar trick with dangerous reach: tampering with trusted software paths to harvest cloud tokens, SSH keys, and Kubernetes secrets.

PyPI Poisoning Hits Telegram Bot Builders, and the Backdoor Hides in Plain Sight

Published: 01 July 2026 02:08Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

A malicious package campaign tied to Telegram bot development shows how a trusted Python repository can become the delivery layer for server-side compromise.

When Shell History Meets Agentic AI, the Risk Moves to the Command Line

Published: 30 June 2026 19:05Category: AI Security & Agentic SystemsAuthor: KERNELWATCHER

Decades-old Bash tricks are being used to test whether open-source AI coding agents can be pushed past their safety checks and into dangerous repository-driven workflows.

Malicious Packages Take the Editor Route: npm and Go Code Abuse VS Code Tasks for Stealth

Published: 29 June 2026 10:57Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A package-chain compromise can do more than slip in bad code - it can turn developer tooling itself into the execution path for a cross-platform Python infostealer.

Package Trust Under Siege: Miasma’s Latest Move Cuts Across npm, GitHub Actions, and Go

Published: 26 June 2026 17:38Category: Malware & BotnetsAuthor: SIGNALMONK

The latest Miasma-linked supply-chain activity shows how a single poisoned release can pressure multiple trust layers at once, from package registries to build automation.