#npm-package-compromise

[ follow ]
Information security
fromSecurityWeek
1 day ago

TanStack, Mistral AI, UiPath Hit in Fresh Supply Chain Attack

A coordinated Mini Shai-Hulud supply chain attack compromised 170+ packages, stealing tokens and credentials and spreading via CI publishing of malicious package versions.
#supply-chain-attack
Information security
fromThe Hacker News
2 months ago

UNC6426 Exploits nx npm Supply-Chain Attack to Gain AWS Admin Access in 72 Hours

UNC6426 exploited stolen GitHub tokens from the nx npm supply chain compromise to completely breach a victim's cloud environment and exfiltrate data within 72 hours.
fromInfoWorld
2 months ago
Information security

Compromised npm package silently installs OpenClaw on developer machines

A compromised npm token caused the Cline CLI to install OpenClaw via a malicious postinstall script, exposing users to an agent with broad system access.
Information security
fromThe Hacker News
2 months ago

UNC6426 Exploits nx npm Supply-Chain Attack to Gain AWS Admin Access in 72 Hours

UNC6426 exploited stolen GitHub tokens from the nx npm supply chain compromise to completely breach a victim's cloud environment and exfiltrate data within 72 hours.
[ Load more ]