#Supply Chain Attack
All CosmicBytez Labs articles tagged #Supply Chain Attack, across news, security advisories, how-to guides, and projects.
- News
101 Malicious npm Packages Hijack Developer WhatsApp Accounts via Baileys Library
OX Security found 101 npm packages abusing the Baileys WhatsApp library to silently enroll developers in scam channels, racking up 490,000 downloads.
- News
Malicious Admin Menu Editor Pro Plugin Backdoors 1,500 WordPress Sites
Malicious Admin Menu Editor Pro updates backdoored 1,500+ WordPress sites after the developer's site was compromised by an attacker.
- News
Head Mare Hacktivists Breach TrueConf to Trojanize Client Installers with PhantomCore Backdoors
The Head Mare hacktivist group exploited two unpatched TrueConf server vulnerabilities to replace legitimate client installers with malicious versions...
- News
Polymarket Customers Lose $3 Million in Supply-Chain Attack
Hackers injected a malicious JavaScript payload into Polymarket's frontend by compromising a third-party vendor, draining approximately $3 million from...
- News
Suspicious Polyfill Login Prompts Pop Up on Toshiba, Muji Websites
Tech giant Toshiba and mega-retailer Muji have warned visitors that suspicious sign-in screens appearing on their websites could be harvesting credentials — a…
- News
Axios npm Hack Used Fake Teams Error Fix to Hijack
The Axios HTTP client post-mortem reveals North Korean threat actors used a ClickFix-style fake Microsoft Teams error message to socially engineer a...
- News
Russian APT 'ChainReaver' Hijacks 50 GitHub Accounts and Mirrors
A Russian state-sponsored APT group dubbed ChainReaver-L compromised trusted file-sharing mirrors and 50 long-established GitHub accounts to distribute...
- News
Supply Chain Attack Discovered in Popular NPM Packages
Security researchers have discovered malicious code injected into several popular NPM packages with millions of weekly downloads. Developers urged to...