supply chain attack
17 stories
Brevo Supply-Chain Attack Infected Over 100,000 Websites
A supply-chain attack on the marketing platform Brevo, formerly Sendinblue, leveraged a compromised Cloudflare API key to inject malicious code into over 100,000 websites. The attackers initially gained access through a SAML SSO vulnerability, compromising customer accounts and exporting data. After blocking the initial breach, they returned and used a stolen Cloudflare API key to deploy a malicious Worker that modified website responses at the edge, bypassing origin server security checks and distributing malware to visitors.

Australian Police Arrest Alleged TeamPCP Cybercrime Masterminds
Australian Federal Police, with assistance from the FBI, have arrested two men suspected of leading the cybercrime group TeamPCP. This group is accused of conducting supply chain attacks by inserting malicious code into open-source software, potentially compromising over 1,000 organizations globally. The attacks led to the theft of hundreds of thousands of credentials and exfiltration of significant data, with estimated global remediation costs in the hundreds of millions of dollars.

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
Researchers have identified 14 malicious npm packages disguised as calendar and streak utilities that deliver a sophisticated Linux backdoor known as RedC2 4.0. These packages, once imported, stealthily execute a Linux implant that communicates with a command-and-control server for post-exploitation activities. The RedC2 framework, marketed as a cross-platform toolkit, features AI-assisted capabilities for orchestrating complex intrusions using natural language commands.

Malware injected into popular Rust packages to steal developer credentials
Malicious actors have compromised several widely-used Rust packages, including arrayref, internment, and append-only-vec, by injecting malware into their build scripts. These poisoned packages, disguised as legitimate updates, were designed to steal developers' credentials. The attack leveraged a typosquatted dependency, proc-macro1, which fetched malware from a remote server during the compilation process. The compromised packages were quickly removed from the registry, but their popularity raises concerns about the potential impact on developers.

Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
Malicious versions of three popular Rust crates were briefly available on crates.io, a package repository, after a compromised maintainer account published them. These releases contained a build script that, during compilation, would download and execute a remote payload. The affected crates were quickly removed, and there is no evidence of widespread use, but developers are advised to check their systems and pin to older, safe versions of the affected libraries.

Hackers poison arrayref Rust crate to push infostealer malware
Hackers compromised the maintainer account for the popular Rust crate `arrayref`, injecting malware that executes during the compilation process on developers' systems. This supply-chain attack also affected two other crates, `append-only-vec` and `internment`, within a short timeframe. The malware, disguised as a dependency, attempts to steal credentials from browsers and establish persistence across various operating systems.

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
A campaign involving nearly 800 malicious npm packages has been discovered, delivering a cross-platform Remote Access Trojan (RAT) and infostealer. These packages, some appearing to be AI-generated or typo-squatted, instruct developers to load them via `require()`, leading to the execution of a downloader. This downloader fetches platform-specific payloads from Cloudflare Workers or uses DNS TXT records for delivery, ultimately deploying malware that can interfere with security monitoring and establish persistence.

In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street
Several cybersecurity incidents are highlighted, including a ban on Chinese data center technology, a supply chain attack on QuickFox VPN, and a phishing breach at IEH Corporation. Additionally, AI-generated content may be impacting Apple's bug bounty program, and a North Carolina port experienced an attack, alongside broader targeting of Wall Street.

TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign
Researchers have linked the threat actor known as TeamPCP to cybercriminal activities dating back to 2020, predating their known supply chain attacks. The group has a history of exploiting vulnerabilities in internet-facing infrastructure, including Redis servers and AI platforms, for various malicious purposes like cryptocurrency mining and botnet creation. Their operations have evolved to include sophisticated supply chain compromises, weaponizing open-source libraries and leveraging cloud infrastructure for widespread attacks.

Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
Advertising technology firm Adform has identified a supply chain attack where hackers compromised a JavaScript file to alter cryptocurrency wallet addresses displayed on client websites. The malicious code, active around July 27, 2026, could replace legitimate wallet addresses with attacker-controlled ones when users copied them or interacted with forms. Adform has since removed the malicious code and notified affected customers, advising them to clear browser caches and verify all wallet addresses before sending funds.

This month in security with Tony Anscombe – July 2026 edition
July 2026 saw significant cybersecurity events including OpenAI models breaching Hugging Face, the first documented agentic ransomware operation named JADEPUFFER, and a new AI-driven supply chain threat known as 'phantom squatting'. These incidents highlight emerging risks associated with AI and autonomous systems in cybersecurity.

Hackers abuse ViPNet software to target Russian govt agencies
An advanced threat actor, potentially Chinese-speaking, is targeting Russian government and other high-value organizations by abusing the update mechanism of ViPNet, a popular Russian cybersecurity product. The campaign, active since at least May and dubbed HelloNet, involves injecting malicious DLLs into the ViPNet update directory, which then load further malware payloads like proxies, backdoors, and log cleaners. Researchers have low confidence in the attribution due to weak evidence.

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver RAT
Researchers have identified seven malicious npm packages that were part of a software supply chain attack targeting the Vite frontend tooling ecosystem. These packages, dubbed ViteVenom, utilized a sophisticated four-tier blockchain-based command-and-control infrastructure across multiple networks to deliver a remote access trojan (RAT).

HalluSquatting Attack Exploits AI Coding Assistants to Deliver Malware
A new attack technique called HalluSquatting leverages the tendency of AI coding assistants to invent non-existent project names. Attackers can register these fabricated names and trick the AI into recommending them, thereby leading users to unknowingly install malicious software like botnet malware.

Texas Parks and Wildlife, WordPress Plugin Vendor Hit by Data Breaches
Several organizations experienced significant security incidents this week. The Texas Parks and Wildlife Department suffered a data breach affecting over 3 million customers due to a vendor compromise, exposing personal information but not financial or social security data. Additionally, a supply chain attack on WordPress plugin vendor ShapedPlugin delivered malicious updates, leading to credential theft and website modifications. AI-powered threats are also on the rise, with a new phishing service called EvilTokens exploiting device-code authentication to steal Microsoft 365 tokens.

29th June – Threat Intelligence Report
Several organizations have reported significant cyber incidents. Polymarket experienced a supply chain attack resulting in the theft of $3 million in cryptocurrency. Japanese telecom KDDI disclosed a breach affecting up to 14.22 million email accounts. Tata Electronics, a supplier to major tech firms, suffered a data breach. Brazil's National Civil Defense platform was targeted with a fake alert, and the US National Association of Insurance Commissioners confirmed a data theft via a zero-day vulnerability. Additionally, a new AI-powered phishing service called EvilTokens has been identified, exploiting authentication methods to steal Microsoft 365 tokens.

Miasma Worm Exploits Developer Credentials in Supply Chain Attacks
A sophisticated supply chain attack, dubbed Miasma, has compromised numerous npm packages, including those under the @redhat-cloud-services namespace. Attackers exploited stolen developer credentials, which lingered in underground markets for weeks before being used to poison software packages. The worm also targeted AI coding assistants, expanding its attack surface to local developer environments.