ProBackend
AI & Software Supply Chain Compromises

AI & Software Supply Chain Compromises

Articles on malicious packages, dependency hijacking, typosquatting, and other supply chain attacks targeting open-source libraries, package managers (npm, PyPI, RubyGems), CI/CD pipelines, and developer tooling.

ai software supply chain compromisesAug 31, 20265 min

187 npm Packages Compromised in Self-Propagating Shai-Hulud Attack

Security researchers uncovered a self-propagating supply chain attack that compromised 187 npm packages, dubbed Shai-Hulud. The malware harvests cloud credentials, injects GitHub Actions backdoors, and automatically spreads to other maintainer packages.

ai software supply chain compromisesJul 1, 20263 min

Operation Navy Ghost: Trojanized Telegram Bot Libraries Compromise Servers

A newly identified PyPI supply chain attack, Operation Navy Ghost, involves malicious forks of the Pyrogram library designed to gain persistent, remote control of Telegram bot infrastructure used by Python developers.