ProBackend
Supply Chain Security

Supply Chain Security

Compromised packages, dependency attacks and the software supply chain.

ai cyber threats nation state actorsJun 29, 20265 min

Sapphire Sleet Weaponized npm to Poison AI Toolchains — and You’re Still Installing Packages Without Checking

Microsoft attributes the Mastra AI supply chain attack to Sapphire Sleet — a North Korean group that turned npm into a silent crypto theft pipeline by hijacking a maintainer account and injecting malicious dependencies into 140 packages.

ai prediction market security incidentsJun 28, 20265 min

Polymarket's $3 Million Supply-Chain Breach: The Attack, the Aftermath, and the Vendor Nobody Named

A compromised third-party vendor allowed hackers to inject malicious JavaScript into Polymarket's website frontend, stealing roughly $3 million in pUSD from fewer than 15 users. Polymarket has patched the vulnerability and promised full reimbursement — but the attacker's path in remains a mystery.

cloud security incidentsJun 28, 20263 min

IronWorm’s Rust Engine Is Rewriting the Rules of Open Source Supply Chain Attacks

A newly discovered Rust-based malware campaign, IronWorm, is hijacking npm packages to steal credentials, self-propagate via Trusted Publishing, and exfiltrate data through GitHub Actions—turning developer workflows into attack vectors.

ai policy ethicsJun 24, 20264 min

How TeamPCP Turned Loose Secrets and Unpinned Actions Into a Supply Chain Juggernaut

An analysis of TeamPCP's Shai-Hulud campaigns, detailing how simple configuration failures, stolen tokens, and unpinned CI/CD workflows allowed an opportunistic threat group to compromise major open-source ecosystems like LiteLLM and TanStack.

education data breach responseJun 23, 20265 min

Credential Leak at Oxford Career Platform Exposes Third-Party Risks in Higher Ed

A comprehensive analysis of the University of Oxford's CareerConnect breach and its implications for higher education supply chain security.

cybersecurityJun 23, 20269 min

IronWorm Malware Hits 36 npm Packages in Supply Chain Attack

A new infostealer malware named IronWorm has compromised 36 packages on the npm index, targeting 86 environment variables and 20 credential files—including OpenAI, AWS, Anthropic, npm credentials, vault configs, SSH keys, and Exodus wallet files. The Rust-based malware hides behind an eBPF rootkit, uses Tor for C2, self-propagates via stolen npm credentials (including Trusted Publishing secrets), and can leverage GitHub Actions to upload exfiltrated data as build artifacts.

venture capital startupsJun 22, 20263 min

Robotic Ike Jime: Can Shinkei Systems Remake the Seafood Supply Chain?

Explore how Shinkei Systems uses AI and computer vision enabled robotics to automate ike jime processing at sea, enhancing seafood quality, increasing shelf-life, and revolutionizing the seafood supply chain sustainability through precision technology.

venture capital startupsJun 22, 20266 min

Founders Fund's Shinkei Bet: A Robotic Rethink of the Fish Supply Chain

Shinkei Systems is aiming to re-shore and automate the fish supply chain, using robotics to perform humane 'ike jime' processing that extends shelf life and improves quality, turning American-caught fish into a premium product. Learn more in our related coverage on physical AI infrastructure: OpenAI's Robotics Relaunch and The Agentic Laboratory.

cloud security incidentsJun 22, 20263 min

Red Hat npm Packages Compromised in Supply-Chain Attack Distributing Miasma Malware

More than 30 npm packages under Red Hat's '@redhat-cloud-services' namespace were compromised in a supply-chain attack distributing the Shai-Hulud credential-stealing malware, dubbed "Miasma."

ai psychologyJun 16, 20265 min

The AI Dependency Paradox: How Chatbot Reliance Weakens Independent News Verification

While AI chatbots can initially boost fact-checking accuracy by 21%, a new MIT Media Lab study reveals a disturbing long-term dependency. As users habituate to AI-assisted verification, their ability to independently detect misinformation significantly degrades, creating a 'GPS effect' where the human mind loses its inherent news-literacy map.

cybersecurityJun 15, 20266 min

SynthWave: AI-Powered Supply Chain Attacks with Model Composition

A deep dive into SynthWave—a previously undocumented cyberattack campaign that uses fine-tuned open-weight LLMs to generate human-like code for supply chain attacks on npm and PyPI. Learn how model composition increased attack success by 300% and what it means for software security.

ai agent security safetyJun 15, 20264 min

The Miasma Worm: A Self-Replicating Supply Chain Attack Targeting AI Coding Agents

The Miasma worm is a credential-stealing supply chain attack framework that has compromised 73 Microsoft-affiliated GitHub repositories. This autonomous worm uses compromised developer credentials to spread through CI/CD pipelines and specifically targets environments with automated AI tools.