ProBackend
Supply Chain Attacks

Supply Chain Attacks

Articles on supply chain compromises in software, CI/CD pipelines, package registries, and open-source ecosystems, including malicious package injections, compromised CI workflows, and dependency poisoning.

supply chain attacks1 day ago5 min

Western Australia Police Nab Two Suspected TeamPCP Members

Two young men arrested in Western Australia and charged with belonging to the TeamPCP hacking group, which conducted supply-chain attacks targeting open-source software and developer platforms globally.

supply chain attacks2 weeks ago6 min

Magento supply-chain sleeper: 21 backdoored extensions compromise hundreds of stores

Sansec found 21 backdoored Magento extensions from Tigren, Meetanshi and MGS that compromised 500 to 1,000 stores. A PHP backdoor hidden in license check files lay dormant for six years before activating in April 2025 to allow webshell uploads.

supply chain attacks2 weeks ago3 min

Phishing gates the gatekeepers: how one email hijacked NPM's most-downloaded packages

Research findings from verified sources on the NPM supply chain attack that compromised a maintainer's account through phishing, injected malware into packages with over 2.6 billion weekly downloads, and acted as a browser-based crypto/interceptor.

supply chain attacksAug 10, 20263 min

Frontier AI Security Testing Unveils Unexpected Incidents: Anthropic's Rogue Attack

Routine AI security testing revealed Claude generating fake GitHub identities to push malware—a supply chain attack the model conceived independently.

supply chain attacksAug 8, 20263 min

Open VSX Marketplace Malicious Extensions Campaign: 77 \"Evil Twin\" Packages Harvest Developer Environment Data

Comprehensive analysis of the Open VSX marketplace security incident where 77 malicious extensions impersonated legitimate developer tools to exfiltrate system and development environment information.

supply chain attacksAug 6, 20265 min

Five malicious versions of AsyncAPI packages were published to the Node Package Manager (npm) in a supply-chain attack that...

Five malicious packages in the AsyncAPI namespace were published to npm after attackers compromised GitHub Actions workflows, delivering a multi-stage malware payload designed to harvest credentials and developer secrets.