T1195.002Compromise Software Supply Chain
T1195.002 — Compromise Software Supply Chain is a MITRE ATT&CK technique in the Initial Access tactic. Clankerusecase tracks 293 detection use cases covering it and 415 threat-intel articles citing it.
Initial Access
293Use cases
415Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1195 · Supply Chain Compromise
Use cases covering this technique (293)
Trusted vendor binary / installer launching unusual children [WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes [WEEKLY] Developer interpreter / package-manager process exfiltrating tokens to public code-hosting / worker domains [WEEKLY] Developer package install spawning script-host with non-registry C2 within 5 minutes [WEEKLY] Install-Time npm/Bun Lifecycle Execution Beaconing Out Within Minutes [WEEKLY] Install-Triggered Registry Publish or Git Push (Supply-Chain Worm Self-Propagation) [WEEKLY] npm-install spawned process performing cred-file fan-out plus IMDS reach [WEEKLY] npm Install-Time Lifecycle Hook Triggers Outbound Egress to Newly-Seen Domain (Shai-Hulud/Miasma/IronWorm pattern) [WEEKLY] npm/node-gyp Install-Hook Spawn Chained to Outbound Egress [WEEKLY] npm/yarn/pnpm Install-Hook Spawn → Credential-Store Read or Worm-Payload Drop in node_modules [WEEKLY] Package install lifecycle hook spawns interpreter that reads developer credential stores [WEEKLY] Package-install lifecycle script harvests local credentials and beacons to a non-baselined domain [WEEKLY] Package-manager child process credential fan-out with public egress (Mini Shai-Hulud / TeamPCP worm chain) [WEEKLY] Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access [WEEKLY] Package-manager install hook spawns interpreter that beacons to non-registry host within 120s [WEEKLY] Package Manager Install Hook Spawns Scripting Interpreter Then Touches Credential Files or Egresses Off-Registry [WEEKLY] Package-Manager Install -> Interpreter Child -> Non-Registry Egress Within 5 Minutes [WEEKLY] Package Manager Install Spawning Outbound Egress to Non-Registry Infrastructure Within 5 Minutes [WEEKLY] Package-manager install-time interpreter spawn with credential-file read and outbound egress within 120s [WEEKLY] Package manager lifecycle hook spawns network-fetching shell or runtime [WEEKLY] Package manager lifecycle hook spawns runtime with outbound egress to non-registry host within 5 minutes [WEEKLY] Package manager spawns network-fetching child to public code-hosting within minutes of install [WEEKLY] Script Interpreter or Package-Install Hook Egress to Free-Tier Edge SaaS Within 5 Minutes of Process Start [WEEKLY] Supply-chain repo credential theft → outbound exfil to attacker infra [WEEKLY] Vendor / Third-Party OAuth App or SP Sign-in From Unbaselined Egress Followed by Bulk SaaS Object Read Hunting 3CXDesktopApp Software Shai-Hulud 2 Exfiltration Artifact Files Windows Vulnerable 3CX Software 3CX Supply Chain Attack Network Indicators GitHub Actions Disable Security Workflow [LLM] CubePilot firmware/file downloaded from cubepilot.org on 24-25 Jul 2026 (possible tampered supply chain) [LLM] Malicious mrmustard 0.7.4 artifact by hash or filename [LLM] Shai-Hulud / GhostAction malicious workflow artifact dropped on runner or repo checkout [LLM] SleeperGem loader: ruby install script spawns shell running deploy.sh [LLM] Trojanized WebEx/Zoom/MobaXterm installer spawns Python or script host (UAT-11795 Starland RAT) [LLM] Compromised @asyncapi npm package versions resolved into node_modules / Yarn cache [LLM] Malicious @velora-dex/sdk (9.4.1/9.4.2) pulled into GitHub Actions build runner [LLM] Shai-Hulud worm artifacts written on GitHub Actions runner (shai-hulud-workflow.yml / bundle.js) [LLM] Compromised @velora-dex/sdk npm package (9.4.1/9.4.2) installed on CI runner [LLM] npm/node lifecycle script fetching Bun runtime from github.com/oven-sh/bun [LLM] Malicious @bitwarden/cli payload artifacts on disk (bw_setup.js, bw1.js, Shai-Hulud markers) [LLM] pip install redirected to non-PyPI index / find-links (dependency confusion) [LLM] Python setup.py install-time code execution spawning shell/LOLBin [LLM] Malicious .pth file dropped into site-packages by pip/python [LLM] Persistent PIP_ index/config environment variable set in registry [LLM] Miasma/AsyncAPI first-stage: node spawns detached 'node -e' downloader referencing IPFS/sync.js [LLM] Shai-Hulud npm worm payload/workflow file drop (bundle.js, setup_bun.js, shai-hulud-workflow.yml) [LLM] plain-crypto-js postinstall RAT dropper spawns downloader (axios/Sapphire Sleet) [LLM] Malicious postmark-mcp BCC email exfiltration to phan@giftshop[.]club [LLM] jscrambler npm supply-chain: malicious dist/intro.js binary container drop [LLM] IronWorm preinstall loader: detached hidden binary executed from OS temp by node.exe [LLM] IronWorm cross-platform payload execution by SHA256 (jscrambler stealer binaries) [LLM] Backdoored @injectivelabs/sdk-ts 1.20.21 payload file dropped on disk [LLM] Sha1-Hulud 2.0 npm worm payload files (setup_bun.js / bun_environment.js) written or executed [LLM] Cloud IMDS credential harvesting by node/npm/bun during package install (Sha1-Hulud/Megalodon) [LLM] TruffleHog secret scanner spawned from an npm/bun package-install context (Sha1-Hulud) [LLM] Malicious @injectivelabs SDK build artifact by SHA-256 on disk [LLM] Transitive install of poisoned @injectivelabs 1.20.21 build under node_modules [LLM] tj-actions/changed-files malicious commit 0e58ed86 referenced on host (CVE-2025-30066) [LLM] Credential harvest via /proc/<pid>/mem read of GitHub Actions Runner.Worker [LLM] GitHub Actions runner spawns network tool / interpreter under compromised trivy-action or KICS [LLM] Phantom Gyp binding.gyp install-time payload execution (Miasma npm worm) [LLM] Compromised @immobiliarelabs Backstage plugin on disk (binding.gyp + index.js / known hashes) [LLM] Java/Spring drops & runs svchosts.exe (svchost masquerade) — Jackson typosquat implant [LLM] Jackson typosquat Cobalt Strike implant hash sighting (Win + macOS/Linux) [LLM] Bun v1.3.13 runtime pulled from GitHub Releases during npm install (Phantom Gyp staging) [LLM] Bun executes dropped temp payload /tmp/p*.js (Miasma stealer launch) [LLM] Compromised simonecorsi/mawesome GitHub Action payload by known hash [LLM] Install of known-malicious JetBrains Marketplace plugin (15 trojanized plugin IDs) [LLM] easy-day-js npm postinstall dropper: node executing setup.cjs --no-warnings [LLM] Mastra easy-day-js postinstall dropper: node setup.cjs --no-warnings [LLM] easy-day-js malicious setup.cjs written/deleted under node_modules [LLM] Miasma/Hades Bun dropper executed via npm/pip lifecycle hook (setup_bun.js / bun_environment.js) [LLM] Shai-Hulud/Miasma malicious GitHub Actions workflow file written to .github/workflows [LLM] Mass npm publish from a developer endpoint (worm self-replication) [LLM] Miasma/Hades auto-exec editor & AI-tool config files dropped in project tree [LLM] Phantom Gyp: malicious binding.gyp executing during npm install [LLM] Hades PyPI startup hook: malicious -setup.pth dropped in site-packages [LLM] Worm propagation: burst of npm/PyPI publishes from a developer machine [LLM] Malicious easy-day-js package installed into node_modules [LLM] npm install pulls malicious easy-day-js dropper (setup.cjs + .pkg marker files) [LLM] Malicious JetBrains Marketplace plugin install (15 DeepSeek/CodeGPT clone IDs) [LLM] Vertex AI model upload to default predictable staging bucket (bucket-squat exposure) [LLM] axios npm RAT C2 beacon to UNC1069 infra (142.11.206.73 / sfrclak.com) [LLM] axios RAT Windows payload drop (6202033.vbs/.ps1, ProgramData\wt) during npm install [LLM] Shai-Hulud npm preinstall Bun bootstrap (setup_bun.js / bun_environment.js) [LLM] TruffleHog secret-scan spawned by npm/node install (Shai-Hulud credential harvest) [LLM] FireAnt MetaKit trojanized setup.exe (SPECTRALVIPER downloader) by known hash [LLM] Malicious 'postmark-mcp' MCP server package present/executing on developer endpoints [LLM] GlassWorm Stage-2 C2 beacon to Vultr-hosted command-and-control IPs [LLM] Bun runtime executed from temp dir running _index.js payload (Hades Campaign) [LLM] Hades import-hook payload artifacts dropped (_index.js, _hooks.py, _runtime.bin, .bun_ran, b.zip) [LLM] Malicious AI coding-agent hook configs written to repo (.claude/.gemini/.cursor/.vscode) [LLM] Miasma Phantom Gyp: python.exe (gyp parser) spawning node index.js during npm install [LLM] Miasma-tainted package install: binding.gyp dropped into known-compromised npm package paths [LLM] Miasma payload SHA256 hash hit (published Phantom Gyp IOCs) [LLM] Phantom Gyp: node-gyp install-time code execution via weaponized binding.gyp [LLM] Miasma GitHub Actions workflow injection for persistence by node payload [LLM] Miasma/Node-gyp loader file hashes present on developer or CI host [LLM] Package manager runtime connecting to durabletask/axios supply-chain C2 IOCs [LLM] Downloader or shell child of npm/pip install (postinstall RAT loader) [LLM] npm preinstall hook executing oversized node index.js from @redhat-cloud-services package [LLM] GitHub bulk git tag force-push by single actor across multiple org repos [LLM] Shai-Hulud npm worm: postinstall bundle.js spawns TruffleHog secret scan [LLM] Shai-Hulud npm worm: malicious GitHub Actions workflow file dropped (.github/workflows/shai-hulud.yaml) [LLM] s1ngularity Nx compromise: telemetry.js postinstall harvesting tokens via gh auth token [LLM] Nx Console v18.95.0 Malicious Payload Bootstrap via Orphan Commit (npx github:nrwl/nx#558b09d7) [LLM] Nx Console v18.95.0 Compromised VSIX / main.js / payload SHA-256 Hash Match [LLM] jqwik-engine 1.10.0 malicious JAR on disk (SHA256 / filename match) [LLM] Maven/Gradle build log file containing jqwik prompt-injection directive [LLM] Miasma worm index.js SHA256 IOC hit (Mini Shai-Hulud variant) [LLM] npm preinstall hook spawns node index.js under @redhat-cloud-services package path [LLM] Install or update of @redhat-cloud-services npm package post-2026-06-01 (IOC version watchlist) [LLM] Mini Shai-Hulud npm worm exfil to filev2.getsession.org [LLM] Shai-Hulud worm GitHub Action workflow file dropped under .github/workflows [LLM] postmark-mcp BCC exfil to giftshop.club [LLM] npm/yarn/pnpm postinstall hook spawning credential-harvest tooling [LLM] Trojanized axios npm package postinstall: node.exe spawned from plain-crypto-js dependency [LLM] npm/pnpm install of trojanized codexui-android package on developer endpoint [LLM] npm/bun process writing GitHub Actions workflow files (worm secret-exfil injection) [LLM] Laravel-Lang supply chain C2/exfil to flipboxstudio.info [LLM] Laravel-Lang stealer file drop in .laravel_locale temp directory [LLM] DebugChromium.exe execution (Laravel-Lang stealer Windows artifact) [LLM] cscript/wscript executing a script from .laravel_locale temp directory [LLM] Compromised laravel-lang Composer package: helpers.php in vendor tree [LLM] cscript.exe launching .vbs from .laravel_locale temp directory [LLM] Composer install of malicious helpers.php in laravel-lang vendor package [LLM] Megalodon backdoor workflow file (SysDiag.yml / Optimize-Build.yml) written to .github/workflows/ [LLM] Compromised Nx Console VS Code extension (nrwl.angular-console v18.94.0/18.95.0/18.100.0) install on endpoint [LLM] Nx Console v18.95.0 compromised extension installed (May 2026 supply-chain attack) [LLM] TeamPCP Nx Console payload SHA256 hash match on developer endpoints [LLM] VS Code child process fetching payload from nrwl/nx orphan commit (Nx Console v18.95.0 dropper) [LLM] Compromised Microsoft durabletask PyPI Package Install (TeamPCP 1.4.1-1.4.3) [LLM] durabletask PyPI dropper launches second-stage zipapp (python3 /tmp/managed.pyz) [LLM] Mini Shai-Hulud npm worm payload by SHA256 [LLM] bun runtime executed on CI runner spawning python3 with sudo escalation [LLM] GitHub workflow references actions-cool/issues-helper or maintain-one-comment by tag [LLM] Compromised node-ipc.cjs bundle write (~117KB) under node_modules [LLM] Mini Shai-Hulud npm preinstall hook spawning bun runtime [LLM] Mini Shai-Hulud Claude Code SessionStart hook injection via npm install [LLM] Outbound egress to node-ipc stealer infrastructure (azurestaticprovider[.]net / 37.16.75.69) [LLM] node-ipc stealer __ntw=1 environment marker in process command line [LLM] Malicious node-ipc package landed on disk under node_modules [LLM] TeamPCP Mini Shai-Hulud stealer payload hash match (SHA256/SHA1) [LLM] Mini Shai-Hulud router_init.js dropped at npm package root in node_modules [LLM] Mini Shai-Hulud npm worm payload dropped under node_modules (router_init.js / tanstack_runner.js / known SHA256) [LLM] Bun spawned with tanstack_runner.js via npm prepare lifecycle (Mini Shai-Hulud) [LLM] Mini Shai-Hulud persistence to ~/.claude/hooks and .vscode/tasks.json by node/npm/bun [LLM] Mini Shai-Hulud Wave 4 (TanStack/TeamPCP) worm payload file created in node_modules [LLM] ScarCruft sqgame supply-chain delivery domain contact (BirdCall/RokRAT) [LLM] BirdCall trojanized APK/mono.dll SHA1 match on Windows endpoints [LLM] Shai-Hulud npm preinstall: node spawns Bun runtime from bun-dl-* tmpdir [LLM] Shai-Hulud AI coding-agent persistence: .claude/settings.json + .vscode/tasks.json drops [LLM] Shai-Hulud known-bad setup.mjs / execution.js SHA256 hash match [LLM] Malicious elementary.pth dropped in Python site-packages [LLM] Install of trojaned elementary-data 0.23.3 via pip / poetry / uv [LLM] Docker / Kubernetes pull of compromised ghcr.io/elementary-data/elementary image [LLM] Bun runtime fetched from github.com/oven-sh/bun during npm install (Bitwarden CLI hijack) [LLM] Known-malicious bw_setup.js / bw1.js SHA256 dropped under @bitwarden/cli [LLM] Mini Shai-Hulud: Python subprocess spawns `_runtime/start.py` from lightning site-packages [LLM] Mini Shai-Hulud PyPI payload known SHA256 (start.py / router_runtime.js) [LLM] lightning PyPI compromise artifacts: start.py / router_runtime.js write [LLM] Python child process executing lightning _runtime/start.py bootstrapper [LLM] npm preinstall hook executes 'node setup.mjs' / 'bun execution.js' (Mini Shai-Hulud SAP supply chain) [LLM] Mini Shai-Hulud known SHA256 IOC match (setup.mjs / execution.js / runner-memory dumper) [LLM] Malicious tanstack npm postinstall hook executing postinstall.cjs [LLM] Known-bad tanstack 2.0.4-2.0.7 package tarball SHA256 file hash on disk [LLM] Mini Shai-Hulud npm preinstall chain: node setup.mjs → bun execution.js [LLM] Mini Shai-Hulud payload file drop: setup.mjs/execution.js by hash & size in node_modules [LLM] Compromised elementary-data==0.23.3 PyPI install on developer / CI host [LLM] npm/PyPI dropper self-cleanup: find rm -rf of kube-health-tools in node_modules [LLM] Shai-Hulud 2.0 npm worm artifact: setup_bun.js / bun_environment.js dropped by node/npm [LLM] Read of /proc/<pid>/mem targeting GitHub Runner.Worker (TeamPCP credential dump) [LLM] TeamPCP sysmon.py systemd-user persistence on developer host [LLM] npm postinstall node setup.js dropper executing from plain-crypto-js with immediate network egress [LLM] Malicious axios or plain-crypto-js package files written to node_modules [LLM] hackerbot-claw second-stage download: curl -sSfL pipe-bash from hackmoltrepeat.com/molt [LLM] hackerbot-claw token exfiltration: curl POST with GITHUB_TOKEN to recv.hackmoltrepeat.com [LLM] npm postinstall chain installs malicious 'openclaw' global package (cline@2.3.0 supply-chain IOC) [LLM] GlassWorm Zig dropper native node addon (win.node/mac.node) written to IDE extension bin/ folder [LLM] Force-install of IDE extension via cmd.exe with --install-extension flag spawned by node host [LLM] Outbound fetch of attacker-controlled autoimport VSIX from ColossusQuailPray GitHub release [LLM] IoliteLabs VSCode extension dropper: VS Code child process reaching rraghh.com / oortt.com C2 [LLM] TeamPCP telnyx FetchAudio() — python subprocess running inline base64 exec [LLM] msbuild.exe dropped to Startup folder (TeamPCP telnyx Windows persistence) [LLM] pip install of malicious telnyx versions 4.87.1 / 4.87.2 [LLM] Compromised litellm 1.82.7 / 1.82.8 PyPI install (TeamPCP supply-chain) [LLM] Outbound C2 to sfrclak.com / 142.11.206.73:8000 (Axios npm RAT beacon) [LLM] npm/node postinstall hook spawning interpreter and reaching new C2 host (Axios-style dropper) [LLM] axios npm RAT C2 beacon to sfrclak.com / 142.11.206.73:8000 [LLM] axios RAT artifact dropped: com.apple.act.mond / wt.exe / ld.py with known SHA256 [LLM] Malicious litellm_init.pth dropped to site-packages by pip (litellm==1.82.8 install artifact) [LLM] Telnyx PyPI compromise: malicious telnyx 4.87.1 / 4.87.2 hash on disk [LLM] TeamPCP supply-chain C2 — outbound to checkmarx[.]zone / 83.142.209.11 [LLM] TeamPCP systemd backdoor — sysmon.py / sysmon.service persistence on CI runner [LLM] Compromised trivy binary (v0.69.4-v0.69.6) execution by SHA1 hash [LLM] bittensor-wallet 4.0.2 backdoor C2 domain contact (opentensor-* lookalikes) [LLM] Compromised bittensor-wallet 4.0.2 source-tarball SHA256 on disk [LLM] Compromised react-native-international-phone-number / react-native-country-select files written to node_modules [LLM] Attacker-controlled scoped npm relay packages on disk (@usebioerhold8733 / @agnoliaarisian7180) [LLM] C2 beaconing to Vercel-hosted Cloudflare-impersonating domains (cloudflareguard / cloudflareinsights) [LLM] npm postinstall SSH-backdoor chain: node spawning sudo ufw allow 22/tcp + chown ~/.ssh [LLM] Malicious typosquat npm packages installed on disk (ts-bign / big-nunber / levex-refa / lint-builder) [LLM] ForceMemo: Node.js v22.9.0 spawned by Python from user home directory [LLM] ForceMemo: Python process queries Solana mainnet RPC endpoint (blockchain dead-drop C2) [LLM] ForceMemo: init.json persistence file or i.js loader dropped by Python in user home root [LLM] GitHub Actions workflow file referencing compromised xygeni/xygeni-action@v5 or backdoored commit 4bf1d4e [LLM] Malicious litellm 1.82.7/1.82.8 wheel install drops litellm_init.pth in site-packages [LLM] VSCode/VSCodium spawning shell or curl to raw.githubusercontent.com/BlokTrooper [LLM] Glassworm stage-2/stage-3 C2 callback to 45.32.150.251 or 217.69.3.152 [LLM] Cacheract memdump.py download/execution on CI runner or developer host [LLM] Installation of unauthorized cline@2.3.0 npm package on developer endpoints [LLM] Secondary payload install: 'npm install -g openclaw' postinstall hook execution [LLM] npm/node post-install (telemetry.js) spawning credential CLIs (gh auth token / npm whoami) — s1ngularity Nx [LLM] Local AI coding agents (claude/gemini/q) launched with permission-bypass flags during package install — s1ngularity [LLM] Shell rc files (.bashrc/.zshrc) modified by package-install process — s1ngularity persistence/shutdown [LLM] Install of Qix-compromised npm package@version (chalk 5.6.1, debug 4.4.2, ansi-styles 6.2.2 et al.) [LLM] XZ Utils (CVE-2024-3094) build-time backdoor extraction from disguised test corpus [LLM] Scavenger npm supply chain: rundll32 executing node-gyp.dll from node_modules (CVE-2025-54313) [LLM] Scavenger loader/install.js dropped into node_modules (known SHA256 or filename match) [LLM] tj-actions/changed-files compromise: self-hosted runner egress to nikitastupin memdump gist (CVE-2025-30066) [LLM] tj-actions/changed-files compromise: memdump.py secret-exfiltration shell pattern on runner (CVE-2025-30066) [LLM] tj-actions/changed-files compromise: malicious commit SHA 0e58ed86... referenced on host (CVE-2025-30066) [LLM] Installation of credential-leaking ClawHub skills (moltyverse-email, buy-anything, prompt-log, youtube-data) [LLM] Dev endpoint contacts ClawHub / skills.sh agent-skill marketplace [LLM] Nx s1ngularity: npm postinstall weaponizes AI CLI tools (claude/gemini/q) for credential recon [LLM] Nx s1ngularity exfiltration via public GitHub repo 's1ngularity-repository' [LLM] tj-actions/changed-files: CI runner pipes gist memdump.py to python to scrape secrets [LLM] Compromised npm package @vietmoney/react-big-calendar@0.26.2 installation (Shai-Hulud 3.0) [LLM] npm/yarn/pnpm/bun lifecycle hook spawning shell or network LOLBin [LLM] SHA1-Hulud worm payload execution via npm preinstall (setup_bun.js / bun_environment.js) [LLM] Malicious '.github/workflows/discussion.yaml' workflow file created by npm/node [LLM] IndonesianFoods npm spam package install on developer/CI endpoint [LLM] IndonesianFoods auto-publish artifact (auto.js / publishScript.js) dropped in node_modules [LLM] Installation or presence of malicious postmark-mcp npm package (v1.0.16+) [LLM] Shai-Hulud bundle.js postinstall payload by known SHA256 hash [LLM] Shai-Hulud persistence artifact: shai-hulud-workflow.yml file dropped on disk [LLM] Install / lockfile mention of the 28 compromised Qix-campaign package@versions [LLM] Node/npm postinstall spawning AI coding agent CLI (s1ngularity execution chain) [LLM] rundll32.exe loading node-gyp.dll dropped by Scavenger-infected npm postinstall (CVE-2025-54313) [LLM] npm registry typosquat npnjs.com — DNS / URL click (eslint-config-prettier maintainer phishing kit) [LLM] Scavenger Loader DLL (node-gyp.dll) written inside node_modules of CVE-2025-54313 packages [LLM] Cursor IDE or VS Code spawning PowerShell/WScript from extensions folder (Solidity Language malware chain) [LLM] Solidity Language malicious Cursor/VS Code extension folder created on disk (solidityai.solidity-* and related) [LLM] Solidity Language Cursor extension known malicious SHA-256 hash present on disk or executed [LLM] Self-hosted GitHub Action runner downloads memdump.py from compromised gist (CVE-2025-30066) [LLM] Malicious tj-actions base64 payload prefix observed in process command line [LLM] Git checkout of compromised tj-actions/changed-files commit on runner host [LLM] Go typosquat module reference: github.com/boltdb-go/bolt in process or build telemetry [LLM] Installation of poisoned Ultralytics PyPI package (v8.3.41 / 8.3.42 / 8.3.45 / 8.3.46) [LLM] GitHub Actions branch-name template injection — bash brace-expansion shell signature [LLM] Browser/proxy fetch of compromised @lottiefiles/lottie-player from unpkg or jsDelivr CDN [LLM] npm/yarn/pnpm install of compromised @lottiefiles/lottie-player versions 2.0.5-2.0.7 [LLM] npm/yarn/pnpm install of himanshutester002 suspicious aliased packages (string-width-cjs et al) [LLM] node_modules/ drop of himanshutester002 supply-chain credibility-laundering packages [LLM] Polyfill.io supply-chain compromise: egress to Funnull-controlled CDN cluster [LLM] Vulnerable xz / liblzma 5.6.0 or 5.6.1 in software inventory (CVE-2024-3094) [LLM] sshd loads compromised liblzma.so.5.6.0 / 5.6.1 (CVE-2024-3094 runtime trigger) [LLM] .NET build (dotnet/MSBuild) spawns git config to harvest user.email [LLM] Vulnerable Moq 4.20.0 or Devlooped.SponsorLink NuGet package landed on endpoint [LLM] macOS Text Replacements exfiltration via `defaults read NSUserDictionaryReplacementItems` [LLM] Install of ypvpctpbamdhxtkzdu malicious package set (django-yauth + siblings) [LLM] node-ipc/peacenotwar protestware drops WITH-LOVE-FROM-AMERICA.txt on Desktop/OneDrive [LLM] node-ipc destructive wiper component ssl-geospec.js written under node_modules\node-ipc\dao [LLM] npm/yarn install-script (postinstall) spawning download LOLBins for secret theft / payload fetch [LLM] node-ipc protestware dropper file 'ssl-geospec.js' written under node_modules\node-ipc [LLM] node-ipc geofencing beacon: node.exe resolving/contacting api.ipgeolocation.io during install [LLM] peacenotwar payload: creation of WITH-LOVE-FROM-AMERICA.txt protest file [LLM] Python interpreter drops EXE sourced from Discord CDN (cyphers/stealthpy PyPI malware) [LLM] npm install-time script executing 'node .' postinstall payload [LLM] npm post-install spawns node confsettingsaaa.js (gxm-reference dropper execution) [LLM] gxm-reference encrypted-payload artifacts written to disk (obfusc/mac/win/lin .enc.js) [LLM] peacenotwar protestware desktop file drop (WITH-LOVE-FROM-AMERICA.txt) [LLM] node-ipc/peacenotwar geo-locate check via ipgeolocation.io from Node runtime [LLM] node-ipc destructive payload artifact (dao/ssl-geospec.js) on disk [LLM] CodeCov Bash Uploader CI env-var exfiltration via curl (<<<<<< ENV marker) [LLM] Known-malicious npm packages flatmap-stream / lyft-dataset-sdk landing on host [LLM] npm/node install hook exfiltrating /etc/passwd, kube config & krb5 ticket via wget --post-file [LLM] Installation of Snyk-flagged malicious npm packages (radar-cms, rcenodejs, paychex-*) [LLM] npm/node install lifecycle spawning interactive or reverse shell [LLM] hacktask typosquat npm package drops postinstall payload 'package-setup.js' [LLM] npm postinstall executes node package-setup.js (crossenv env-var harvester) [LLM] Vulnerable npm/yarn/pnpm version exposed to bin-key file overwrite (CVE-2019-16776/16777/10773) [LLM] npm/yarn/pnpm planting or overwriting a binary in a system bin directory [LLM] Typosquatted PyPI package install: jeIlyfish / python3-dateutil [LLM] Form-skimmer exfil to js-metrics.com (malicious angular-bmap / ng-ui-library npm versions) [LLM] Install of malicious npm package versions angular-bmap@0.0.9 / ng-ui-library@1.0.987 [LLM] npm/yarn dependency fetched from non-registry source (lockfile resolved-URL hijack) [LLM] npm/yarn install lifecycle (postinstall) spawning download or LOLBin tooling [LLM] Malicious bootstrap-sass 3.2.0.3 gem implant on disk (middleware.rb backdoor / SHA256) [LLM] Bower archive extraction arbitrary file write to sensitive paths (CVE-2019-5484 / Zip Slip) [LLM] Malicious flatmap-stream npm package present in node_modules (event-stream supply-chain backdoor) [LLM] Malicious npm flatmap-stream / event-stream@3.3.6 dependency dropped to endpoint diskArticles citing this technique (415)
crit CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking art-74
crit Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE art-75
crit Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller art-97
crit Don’t swing at everything art-106
high Find Unused, Stale, and OIDC-Replaceable GitHub Actions Secrets Across Your GitHub Organization art-114
crit Begun, the Patch Wars have art-150
crit 10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions art-253
crit 400+ AUR Packages Hijacked: What the “Atomic Arch” Campaign Means for Supply-Chain Security art-316
high Miasma and Hades Are Spreading Now: Detect Them on Developer Machines with Suspicious Files art-317
high Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp art-362
high Miasma supply chain attack: malicious code found in @redhat-cloud-services npm packages art-380
med How Relay Network Adopted AI Coding Securely and Built the Foundation for Agentic Development art-383
high GitHub breached via a malicious VS Code extension: why developer devices are the real target art-412
high The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised art-422
high Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again! art-423
crit Malicious node-ipc versions published to npm in suspected maintainer account compromise art-431
crit Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack art-440
crit Security metamorphosis: a Mythos-ready architecture checklist for autonomous AI attacks art-454
high "A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages art-471
high Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers art-475
med Dev Machine Guard Is Now Open Source: See What's Really Running on Your Developer Machine art-524
high CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Ecosystem art-551
crit Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys art-555
crit ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push art-556
med Snyk and uv, Better Together art-618
med Weaving Security into the Flow: New Snyk Studio Capabilities Power the AI Security Fabric art-634
high 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) art-640
med How Snyk Helps Federal Agencies Prepare for the Genesis Mission Era of AI-Driven Science art-745
med What an 'Aha' Moment with an Org Admin Token Taught One DevSecCon Speaker About AI Security art-856
med Understanding CRA Compliance: Overcoming Challenges with an Integrated Security Testing Approach art-916
med Snyk-Generated SBOMs Now Include License Details for the Open Source Libraries in Your Projects art-1129
med A developer’s best friend: Lessons learned from our canine companions about AI code security art-1246
crit The XZ backdoor CVE-2024-3094 art-1369
med Snyk's AppSec dream team art-1377
med AppSec Maturity Models art-1380
high Snyk Apps now GA: An easy, standardized, and secure framework for building custom integrations art-1488
crit Lessons from OpenSSL vulnerabilities part 2: Finding and fixing supply chain vulnerabilities art-1749
high Securing the web (forward) art-1803
high Cybersecurity Hygiene 101 art-1824
med When software isn’t a “supply” art-1841
med Snyk's AppSec journey in 2022 art-1868
crit Snyk finds 200+ malicious npm packages, including Cobalt Strike dependency confusion attacks art-2203
high Snyk joins OpenSSF: Tackling open source supply chain security with a developer-first approach art-3066
high Detect and prevent dependency confusion attacks on npm to maintain supply chain security art-3088
high New Gartner Market Guide highlights the importance of Software Composition Analysis (SCA) art-3309