extension supply chain
-
Malicious Ruby gems linked to SleeperGem supply chain attack
Researchers said three malicious Ruby gems were published to RubyGems in a supply chain campaign called SleeperGem. The packages were built to load further payloads on developer machines and avoid build systems.
-
Study says AI coding agent skill scanners can be evaded with simple cloaking tricks
Researchers say scanners for malicious AI coding agent skills can be bypassed with simple cloaking tricks, with one method evading every scanner tested more than 90% of the time. A runtime checker caught most hidden threats in tests.
-
Ransomware groups use Citrix flaw, stolen VPN logins and supply chain credentials
Ransomware crews tied to Anubis, The Gentlemen, VECT and TeamPCP are using Citrix exploitation, valid VPN credentials, BYOVD techniques and supply chain access to break into targets and move through networks.
-
Malicious npm packages found posing as PostCSS tools to deliver Windows RAT
Researchers found three malicious npm packages posing as PostCSS tools that delivered a Windows remote access trojan. The campaign used a multi-stage install chain to steal Chrome credentials, run commands and contact an external server.
-
144 Mastra npm packages hit by supply chain attack
A supply chain attack compromised 144 npm packages in the Mastra namespace in June 2026, with a malicious dependency used to drop payloads that could steal wallet data, browser information and credentials.
-
GitHub to disable npm install scripts by default in version 12
GitHub said npm version 12 will disable install scripts by default next month to curb supply chain abuse. The change will also restrict Git and remote dependencies unless users explicitly allow them.
-
Microsoft removes 73 GitHub repositories during malware investigation
Microsoft removed 73 GitHub repositories on June 5 while investigating potential malicious content, briefly disrupting developer pipelines tied to Azure Functions. Researchers linked the incident to a broader Miasma and Shai-Hulud supply-chain campaign.
-
Malicious PyPI packages tied to Hades attack wave, researchers say
Researchers said a new Hades supply chain campaign poisoned 37 wheel artifacts across 19 PyPI packages, using startup hooks to run Bun-based malware that sought cloud, repository and developer credentials.
-
VS Code adds 2 hour delay for extension auto updates
Microsoft has added a two hour delay before Visual Studio Code auto updates most extensions, a move aimed at limiting supply chain risk. Trusted publishers are exempt, and users can still update manually.
-
New npm supply chain worms hit 50-plus packages, steal secrets
Two npm supply chain attacks spread a Rust information stealer and a worm across dozens of packages, targeting developer secrets, cloud credentials and AI tool configurations. Researchers said the malware used GitHub and npm features to keep propagating.







