37 results found
JFrog, a technology company, disclosed on July 5, 2026, that threat actors with ties to North Korea have been linked to two malicious npm packages, "r...
Polymarket, a cryptocurrency-based prediction market platform, suffered a supply chain attack after a third-party frontend vendor was breached. The in...
Red Hat, a leading open-source technology company, suffered a supply chain attack where attackers backdoored 32 packages within its official npm scope...
Arch Linux, a technology organization, suffered a supply chain attack where over 400 packages in the Arch User Repository (AUR) were hijacked. The bre...
ESET researchers disclosed a supply-chain attack targeting the Yanbian gaming community in China, attributed to the North Korean APT group ScarCruft (...
Texas Parks and Wildlife Department (TPWD) experienced a data breach through its license system vendor, exposing sensitive personal information of ind...
Mastra, an open-source JavaScript and TypeScript framework for building AI applications, suffered a software supply chain attack in which 144 npm pack...
JetBrains, a Czech technology company known for its integrated development environments (IDEs), disclosed that at least 15 malicious plugins were disc...
Grafana Labs, a US-based technology company, confirmed a data breach resulting from the TanStack supply chain attack. The breach was publicly disclose...
Microsoft, a global technology company, suffered a supply chain attack when the Miasma worm compromised 73 of its GitHub repositories. The breach was...
The NPM software supply chain was targeted by a Rust-written malware campaign named IronWorm, disclosed in June 2026. The campaign specifically target...
Lightning AI, a technology company, suffered a supply chain attack when threat actors compromised the popular Python package Lightning on PyPI. Two ma...