18 Aug, 2026

BdThemes plugins supply-chain hack creates rogue WordPress admins

A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators’ browsers to create rogue admin accounts. Starting Saturday, the affected BdThemes products were no longer available for download after the WordPress Plugins team closed all of them pending a full […]

3 mins read

Massive ChainDrop npm supply-chain attack infects hundreds of packages

Self-propagating malware named ‘ChainDrop’ has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry. Infected packages include very popular ones such as Keyv and Cacheable, flat-cache and file-entry-cache, all caching utilities from the same maintainer.  The supply-chain attack started after the threat actor compromised the GitHub account of Keyv’s maintainer, and […]

4 mins read

Online ad firm Adform’s script compromised to steal cryptocurrency

Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors’ clipboards with ones controlled by an attacker. Adform is one of Europe’s largest adtech firms, providing a full-stack platform that includes Demand-Side Platform (DSP), Supply-Side Platform (SSP), ad servers, and management […]

3 mins read

Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers

Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers. The cloud computing giant linked the compromises of the typo-crypto, debug, chalk, and axios libraries to the Sapphire Sleet threat actor, also known as BlueNoroff and Stardust Chollima. Initial activity started with trojanizing the typo-crypto […]

2 mins read

GitHub, PyPI add time-based defenses against supply chain attacks

GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact. Specifically, Dependabot comes with a default three-day cooldown setting, while PyPI will reject new files uploaded to releases older than 14 days. The measure comes after the two […]

2 mins read

AsyncAPI npm packages infected with credential-stealing malware

Five malicious versions of AsyncAPI packages were published to the Node Package Manager (npm) in a supply-chain attack that delivered a remote access trojan with info-stealing capabilities. The threat actor exploited a misconfigured GitHub Actions workflow and pushed trojanized packages in the @asyncapi namespace that had a cummulative weekly download count of more than 2.25 […]

3 mins read

Hackers backdoor Jscrambler npm package with infostealer malware

The Jscrambler client-side web security company disclosed that a threat actor published a malicious version of its npm package that has been downloaded almost 1,500 times. The malicious Jscrambler package spanned releases 8.14, 8.16, 8.17, and 8.20 and included information-stealing malware that executed during the ‘preinstall’ hook. “Today, we identified the unauthorized publication of a […]

2 mins read

OpenMandriva Linux says contributor tried to sabotage the project

The OpenMandriva Linux project announced that it was the target of an attempted act of internal sabotage after a dispute among contributors. The attempted destructive action extended from wiping GitHub repositories to pushing an empty package that could have damaged users’ systems. OpenMandriva is an independent, community-run Linux distribution, forked from Mandriva Linux in 2012 […]

3 mins read

Injective SDK on npm infected with cryptocurrency wallet stealer

Hackers compromised the Injective Labs SDK project’s GitHub repository and used it to publish a malicious package on the Node Package Manager (npm) that stole cryptocurrency wallet private keys and mnemonic seed phrases. Application security companies Socket, Ox Security, and StepSecurity detected the supply-chain attack via version 1.20.21 of the @injectivelabs/sdk-ts npm package. Injective SDK […]

2 mins read

Polymarket customers lose $3 million in supply-chain attack

Polymarket says it will fully reimburse customers who lost an estimated $3 million after hackers injected a malicious script into the platform’s frontend following a breach at a third-party vendor. The company states in a brief announcement that the hack was the result of a supply-chain attack that impacted a dependency on its website. Polymarket […]

1 min read