Administrative Betrayal: The Bitwarden CLI Supply Chain Hijack

A malicious npm package impersonating the Bitwarden CLI installed its own runtime to steal secrets. When security tools are the attack vector, the whole CI/CD pipeline becomes a weapon.

Read More

The 48-Hour Secrets Sprint: How Three Registries Were Swept in One Weekend

A coordinated 48-hour sprint hit npm, PyPI, and Docker Hub, targeting developer secrets at scale. From infected AI libraries to a trojanized security scanner, the supply chain is moving faster than your detection.

Read More

North Korea Backdoored Axios for Three Hours. That Was Enough.

DPRK hackers hijacked the Axios npm package, deploying a self-erasing backdoor across 100 million weekly downloads. Three hours was all they needed.

Read More

Anthropic Accidentally Put Claude Code's Source on npm. Again.

Read More

Axios Was Backdoored to Install a RAT. And It Left No Traces.

Read More

This Malware Hides Its Command Server in the Blockchain, and Borrows Google Calendar Too

GlassWorm targets developers through compromised npm, PyPI, and GitHub packages. Its C2 address is hidden in a Solana blockchain memo. You can't take down a blockchain transaction.

Read More

The npm Ghost: That Install Log Looked Normal Because It Was Built to Fool You

Seven malicious npm packages have been stealing sudo passwords and crypto wallet data from developer machines since February. The trick: they generate fake terminal output so convincing that developers don't look twice.

Read More

CanisterWorm: How TeamPCP Hijacked Your Security Scanners and Built an Untakeable Botnet

TeamPCP compromised Trivy and KICS CI/CD scanner tags, spread CanisterWorm to 47 npm packages, and deployed a Kubernetes wiper targeting Iranian timezones -- all controlled via blockchain C2 that can't be taken down.

Read More

North Korea Behind Polyfill.io? Supply Chain Poisoning Just Got a State Sponsor

Forensic research links the Polyfill.io supply chain attack to a North Korean operative. The same week, a CVSS 9.8 RCE hits the simple-git npm library. Your dependency graph is your attack surface.

Read More

Developer Supply Chains Under Coordinated Assault: 88 Malicious npm Packages and a CVSS 9.8 in simple-git

PhantomRaven dropped 88 malicious npm packages targeting AWS credentials and CI secrets. A critical RCE in simple-git threatens millions of dev environments. Your developer toolchain is a target.

Read More