North Korean Hacker Suspected in 3CX Software Supply Chain AttackInfosecurity Magazine·Apr 20, 17:30 UTC · Apr 20, 2023Malware42
LofyGang Group Linked to Recent Software Supply Chain AttacksInfosecurity Magazine·Oct 7, 18:00 UTC · Oct 7, 2022Malware42
Quasar Linux RAT Steals Developer Credentials for Software Supply Chain CompromiseThe Hacker News·May 8, 11:00 UTC · May 8, 2026Malware42
Massive Malicious NPM Package Attack Threatens Software Supply ChainsRecorded Future·May 26, 00:00 UTC · May 26, 2026Malware42
A New Software Supply‑Chain Attack Targeted Millions With SpywareThe Hacker News·Feb 2, 03:40 UTC · Feb 2, 2021Malware42
Researchers Discover Malicious PyPI Package Posing as SentinelOne SDK to Steal DataThe Hacker News·Dec 20, 05:29 UTC · Dec 20, 2022Malware42
3CX Breach Was a Double Supply Chain CompromiseKrebs on Security·Apr 21, 02:22 UTC · Apr 21, 2023Malware42
W4SP Stealer Constantly Targeting Python Developers in Ongoing Supply Chain AttackThe Hacker News·Nov 19, 04:11 UTC · Nov 19, 2022Malware42
Chainguard Libraries for JavaScript provides developers with malware-free dependenciesHelp Net Security·Sep 25, 00:00 UTC · Sep 25, 2025Malware42
VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain AttacksThe Hacker News·Jun 8, 17:09 UTC · Jun 8, 2026Malware42
27 Malicious PyPI Packages with Thousands of Downloads Found Targeting IT ExpertsThe Hacker News·Nov 17, 12:15 UTC · Nov 17, 2023Malware42
20 Popular npm Packages With 2 Billion Weekly Downloads Compromised in Supply Chain AttackThe Hacker News·Sep 10, 00:27 UTC · Sep 10, 2025Malware42
Researchers Uncover Backdoor in Solana's Popular Web3.js npm LibraryThe Hacker News·Dec 6, 03:34 UTC · Dec 6, 2024MalwareCVE-2024-5413447
Over 67,000 Fake npm Packages Flood Registry in WormThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2025Malware42
Beware, Developers: BlazeStealer Malware Discovered in Python Packages on PyPIThe Hacker News·Nov 9, 04:36 UTC · Nov 9, 2023Malware42
Watch Out: These PyPI Python Packages Can Drain Your Crypto WalletsThe Hacker News·Mar 12, 15:56 UTC · Mar 12, 2024Malware42
Software Supply-Chain Attack Hits Vietnam Government Certification AuthorityThe Hacker News·Dec 18, 04:56 UTC · Dec 18, 2020Malware42
Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer AccountThe Hacker News·May 21, 05:56 UTC · May 21, 2026Malware42
Carderbee Attacks: Hong Kong Organizations Targeted via Malicious Software UpdatesThe Hacker News·Mar 19, 18:54 UTC · Mar 19, 2026Malware42
Malware Strains Targeting Python and JavaScript Developers Through Official RepositoriesThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2022Malware142
Malicious npm Packages Exploit Ethereum Smart ContractsInfosecurity Magazine·Sep 3, 15:45 UTC · Sep 3, 2025Malware42
Solana's popular web3.js library backdoored in supply chain compromiseHelp Net Security·Dec 6, 09:08 UTC · Dec 6, 2024Malware42
Compromised dYdX npm and PyPI Packages Deliver Wallet Stealers and RAT MalwareThe Hacker News·Feb 6, 08:40 UTC · Feb 6, 2026Malware42
Rspack npm Packages Compromised with Crypto Mining Malware in Supply Chain AttackThe Hacker News·Dec 21, 08:59 UTC · Dec 21, 2024Malware42
GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack InfrastructureThe Hacker News·May 27, 15:23 UTC · May 27, 2026Malware42
Ongoing supply chain attack targets Python developers with WASP StealerSecurity Affairs·Nov 18, 08:24 UTC · Nov 18, 2022Malware142
Cryptocurrency Stealer Malware Distributed via 13 NuGet PackagesThe Hacker News·Apr 12, 03:41 UTC · Apr 12, 2023Malware42
Malicious PyTorch Lightning update hits AI supply chain securitySecurity Affairs·May 6, 07:04 UTC · May 6, 2026Malware42
Alert: Malicious PyPI Package soopsocks Infects 2,653 Systems Before TakedownThe Hacker News·Oct 2, 13:07 UTC · Oct 2, 2025Malware42
Malicious npm Package Targets Atomic Wallet, Exodus Users by Swapping Crypto AddressesThe Hacker News·Apr 10, 14:18 UTC · Apr 10, 2025Malware42
Over a Dozen Malicious npm Packages Target Roblox Game DevelopersThe Hacker News·Aug 23, 06:37 UTC · Aug 23, 2023Malware42
PyPI Halts Sign-Ups Amid Surge of Malicious Package Uploads Targeting DevelopersThe Hacker News·Mar 30, 05:08 UTC · Mar 30, 2024Malware42
Microsoft revealed details of a supply chain attack at unnamed Maker of PDF EditorSecurity Affairs·Jul 28, 08:32 UTC · Jul 28, 2018Malware42
Malicious npm Packages Found Using Image Files to Hide Backdoor CodeThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2024Malware42
Researchers Hijack Popular NPM Package with Millions of DownloadsThe Hacker News·Feb 17, 04:29 UTC · Feb 17, 2023Malware42
PyPI Python Library "aiocpa" Found Exfiltrating Crypto Keys via Telegram BotThe Hacker News·Nov 29, 08:53 UTC · Nov 29, 2024Malware42
Node.js Users Beware: Manifest Confusion Attack Opens Door to MalwareThe Hacker News·Jul 5, 09:00 UTC · Jul 5, 2023Malware42
Injective Labs GitHub Compromise Pushes Wallet-KeyThe Hacker News·Jul 10, 17:54 UTC · Jul 10, 2026Malware42