supply chain

New Shai-Hulud malware wave compromises 600 npm packages News

New Shai-Hulud malware wave compromises 600 npm packages

Threat actors earlier today published more than 600 malicious packages to the Node Package Manager (npm) index as part o...
Popular node-ipc npm package compromised to steal credentials News

Popular node-ipc npm package compromised to steal credentials

Hackers have injected credential-stealing malware into newly published versions of node-ipc, a popular inter-process com...
Shai Hulud 攻撃、悪意のある TanStack、Mistral npm パッケージを出荷 News

Shai Hulud 攻撃、悪意のある TanStack、Mistral npm パッケージを出荷

開発者を標的とした認証情報を盗むマルウェアを配信する新たな Shai-Hulud サプライチェーンキャンペーンにおいて、npm および PyPI の数百のパッケージが侵害されました。 攻撃者は有効な OpenID Connect (OIDC...
CheckMarx Jenkinsの公式パッケージがinfostealerで侵害される News

CheckMarx Jenkinsの公式パッケージがinfostealerで侵害される

Checkmarx社は週末、同社のJenkins Application Security Testing (AST)プラグインの不正バージョンがJenkins Marketplaceで公開されたことを警告した。 この侵害はTeamPCPハ...
DAEMONツール、サプライチェーン攻撃でトロイの木馬化されバックドアを展開 News

DAEMONツール、サプライチェーン攻撃でトロイの木馬化されバックドアを展開

ハッカーはDAEMON Toolsソフトウェアのインストーラーをトロイの木馬化し、4月8日以降、公式ウェブサイトから製品をダウンロードした数千のシステムにバックドアを配信した。 このサプライチェーン攻撃により、100カ国以上で数千件の感染が...
バックドアされたPyTorch Lightningパッケージがクレデンシャル・ステアラーを落とす News

バックドアされたPyTorch Lightningパッケージがクレデンシャル・ステアラーを落とす

Python Package Index(PyPI)で公開されているPyTorch Lightningパッケージの悪意のあるバージョンは、ブラウザ、環境ファイル、クラウドサービスを標的とした認証情報を盗むペイロードを配信する。 開発者は4月...
PyPI package with 1.1M monthly downloads hacked to push infostealer News

PyPI package with 1.1M monthly downloads hacked to push infostealer

An attacker pushed a malicious version of the popular elementary-data package Python Package Index (PyPI) to steal sensi...
New Checkmarx supply-chain breach affects KICS analysis tool News

New Checkmarx supply-chain breach affects KICS analysis tool

Hackers have compromised Docker images, VSCode and Open VSX extensions for the Checkmarx KICS analysis tool to harvest s...
New npm supply-chain attack self-spreads to steal auth tokens News

New npm supply-chain attack self-spreads to steal auth tokens

A new supply chain attack targeting the Node Package Manager (npm) ecosystem is stealing developer credentials and attem...
CPUIDがハッキングされ、CPU-ZやHWMonitorのダウンロード経由でマルウェアが配信される News

CPUIDがハッキングされ、CPU-ZやHWMonitorのダウンロード経由でマルウェアが配信される

ハッカーは、CPUIDプロジェクトのAPIにアクセスし、人気のあるCPU-ZとHWMonitorツールの悪意のある実行可能ファイルを提供するために公式ウェブサイトのダウンロードリンクを変更した。 この2つのユーティリティは、コンピュータ内部...