AI & Software Supply Chain Compromises
AI & Software Supply Chain Compromises
Articles on malicious packages, dependency hijacking, typosquatting, and other supply chain attacks targeting open-source libraries, package managers (npm, PyPI, RubyGems), CI/CD pipelines, and developer tooling.
ai software supply chain compromisesAug 31, 20265 min
187 npm Packages Compromised in Self-Propagating Shai-Hulud Attack
Security researchers uncovered a self-propagating supply chain attack that compromised 187 npm packages, dubbed Shai-Hulud. The malware harvests cloud credentials, injects GitHub Actions backdoors, and automatically spreads to other maintainer packages.
ai software supply chain compromisesJul 1, 20263 min
Operation Navy Ghost: Trojanized Telegram Bot Libraries Compromise Servers
A newly identified PyPI supply chain attack, Operation Navy Ghost, involves malicious forks of the Pyrogram library designed to gain persistent, remote control of Telegram bot infrastructure used by Python developers.