Supply Chain Security
Compromised packages, dependency attacks and the software supply chain.
Sapphire Sleet Weaponized npm to Poison AI Toolchains — and You’re Still Installing Packages Without Checking
Microsoft attributes the Mastra AI supply chain attack to Sapphire Sleet — a North Korean group that turned npm into a silent crypto theft pipeline by hijacking a maintainer account and injecting malicious dependencies into 140 packages.
Polymarket's $3 Million Supply-Chain Breach: The Attack, the Aftermath, and the Vendor Nobody Named
A compromised third-party vendor allowed hackers to inject malicious JavaScript into Polymarket's website frontend, stealing roughly $3 million in pUSD from fewer than 15 users. Polymarket has patched the vulnerability and promised full reimbursement — but the attacker's path in remains a mystery.
IronWorm’s Rust Engine Is Rewriting the Rules of Open Source Supply Chain Attacks
A newly discovered Rust-based malware campaign, IronWorm, is hijacking npm packages to steal credentials, self-propagate via Trusted Publishing, and exfiltrate data through GitHub Actions—turning developer workflows into attack vectors.
How TeamPCP Turned Loose Secrets and Unpinned Actions Into a Supply Chain Juggernaut
An analysis of TeamPCP's Shai-Hulud campaigns, detailing how simple configuration failures, stolen tokens, and unpinned CI/CD workflows allowed an opportunistic threat group to compromise major open-source ecosystems like LiteLLM and TanStack.
Credential Leak at Oxford Career Platform Exposes Third-Party Risks in Higher Ed
A comprehensive analysis of the University of Oxford's CareerConnect breach and its implications for higher education supply chain security.
IronWorm Malware Hits 36 npm Packages in Supply Chain Attack
A new infostealer malware named IronWorm has compromised 36 packages on the npm index, targeting 86 environment variables and 20 credential files—including OpenAI, AWS, Anthropic, npm credentials, vault configs, SSH keys, and Exodus wallet files. The Rust-based malware hides behind an eBPF rootkit, uses Tor for C2, self-propagates via stolen npm credentials (including Trusted Publishing secrets), and can leverage GitHub Actions to upload exfiltrated data as build artifacts.
Robotic Ike Jime: Can Shinkei Systems Remake the Seafood Supply Chain?
Explore how Shinkei Systems uses AI and computer vision enabled robotics to automate ike jime processing at sea, enhancing seafood quality, increasing shelf-life, and revolutionizing the seafood supply chain sustainability through precision technology.
Founders Fund's Shinkei Bet: A Robotic Rethink of the Fish Supply Chain
Shinkei Systems is aiming to re-shore and automate the fish supply chain, using robotics to perform humane 'ike jime' processing that extends shelf life and improves quality, turning American-caught fish into a premium product. Learn more in our related coverage on physical AI infrastructure: OpenAI's Robotics Relaunch and The Agentic Laboratory.
Red Hat npm Packages Compromised in Supply-Chain Attack Distributing Miasma Malware
More than 30 npm packages under Red Hat's '@redhat-cloud-services' namespace were compromised in a supply-chain attack distributing the Shai-Hulud credential-stealing malware, dubbed "Miasma."
The AI Dependency Paradox: How Chatbot Reliance Weakens Independent News Verification
While AI chatbots can initially boost fact-checking accuracy by 21%, a new MIT Media Lab study reveals a disturbing long-term dependency. As users habituate to AI-assisted verification, their ability to independently detect misinformation significantly degrades, creating a 'GPS effect' where the human mind loses its inherent news-literacy map.
SynthWave: AI-Powered Supply Chain Attacks with Model Composition
A deep dive into SynthWave—a previously undocumented cyberattack campaign that uses fine-tuned open-weight LLMs to generate human-like code for supply chain attacks on npm and PyPI. Learn how model composition increased attack success by 300% and what it means for software security.
The Miasma Worm: A Self-Replicating Supply Chain Attack Targeting AI Coding Agents
The Miasma worm is a credential-stealing supply chain attack framework that has compromised 73 Microsoft-affiliated GitHub repositories. This autonomous worm uses compromised developer credentials to spread through CI/CD pipelines and specifically targets environments with automated AI tools.