Newsgather

supply chain attack

مستقر8 خبر5 مصادرآخر تحديث: 10‏/7‏/2026

أحدث الأخبار

Hackers Compromise Injective Software Package in Supply Chain Attack
يتطور
تقنية·10‏/7‏/2026ملخص الذكاء الاصطناعي

Hackers Compromise Injective Software Package in Supply Chain Attack

A popular npm package for the Injective blockchain was compromised in a supply chain attack, with malware designed to steal crypto wallet private keys and seed phrases. The malicious code, present in version 1.20.21 of the @injectivelabs/sdk-ts package, has been removed, and affected versions deprecated, with no funds on the network reported at risk.

C
Cointelegraph
3 د قراءة
Checkmarx Hit by Supply Chain Attack, Then Ransomware in Cascading Security Breaches
يتطور
تقنية·29‏/4‏/2026ملخص الذكاء الاصطناعي

Checkmarx Hit by Supply Chain Attack, Then Ransomware in Cascading Security Breaches

Checkmarx, a security firm, has suffered a devastating series of breaches over 40 days. It was first compromised through a supply-chain attack on the Trivy vulnerability scanner on March 19, with attackers pushing malware that stole credentials. Checkmarx's own GitHub account was then breached on March 23, pushing malware to its users. Despite remediation, a new malware wave appeared April 22. The Lapsu$ ransomware group subsequently dumped stolen data on the dark web on March 30, originating from Checkmarx's GitHub repositories. Another security firm, Bitwarden, was also affected in the same Trivy supply-chain attack.

A
Ars Technica
2 د قراءة
Open Source element-data Package Compromised in Supply Chain Attack
مُلِح
تقنية·27‏/4‏/2026ملخص الذكاء الاصطناعي

Open Source element-data Package Compromised in Supply Chain Attack

A supply chain attack compromised element-data, an open source CLI for monitoring ML systems. Attackers exploited a vulnerability in a GitHub action to steal developer account tokens and signing keys, then published malicious version 0.23.3 that scraped credentials from infected systems. The package was removed within 12 hours, but users who installed it should assume credentials were exposed and rotate all sensitive access keys immediately.

A
Ars Technica
2 د قراءة