ThreatCluster
  • Feed
  • Saved
THREAT HUNTING
  • Domains
  • IP Addresses
  • File Hashes
  • CVEs
THREAT INTELLIGENCE
  • APT Groups
  • Ransomware Groups
  • Malware Families
  • Attack Types
  • MITRE ATT&CK
  • Security Standards
  • Vulnerability Types
BUSINESS INTELLIGENCE
  • Companies
  • Industry Sectors
  • Security Vendors
  • Government Agencies
  • Countries
  • Platforms
Home / Feed / Article

Supply-chain attacks on open source software are getting out of hand

Threat Score:
53
Ars Technica
1 day ago
Part of cluster #1351
Supply-chain attacks on open source software are getting out of hand

Overview

It has been a busy week for supply-chain attacks targeting open source software available in public repositories, with successful breaches of multiple developer accounts that resulted in malicious packages being pushed to unsuspecting users. The latest target,according tosecurity firm Socket, is JavaScript code available on repository npm. A total of 10 packages available from the npm page belonging to global talent agency Toptal contained malware and were downloaded by roughly 5,000 users befor...

Continue Reading on Original Site

Related Articles

5 articles
1
Allianz Life confirms data breach impacts majority of 1.4 million customers

Allianz Life confirms data breach impacts majority of 1.4 million customers

BleepingComputer • 4 hours ago

Allianz Life confirms data breach impacts majority of 1.4 million customers Lawrence Abrams July 26, 2025 02:00 PM 0 Insurance company Allianz Life has confirmed that the personal information for the "majority" of its 1.4 million customers was exposed in a data breach that occurred earlier this month. "On July 16, 2025, a malicious threat actor gained access to a third-party, cloud-based CRM system used by Allianz Life Insurance Company of North America (Allianz Life)," an Allianz Life spokesper

Score
77
Read more
2

Allianz Life says ‘majority’ of customers’ personal data stolen in cyberattack

TechCrunch • 9 hours ago

Exclusive: Allianz Life said the "majority" of its customers and employees had data stolen in the July cyberattack. The insurance giant has more than 125 million customers worldwide.

Score
69
Read more
3

Hackers Compromised Official Gaming Mouse Software to Deliver Windows-based Xred Malware

Cybersecurity News • 12 hours ago

Gaming peripheral manufacturer Endgame Gear has confirmed that hackers successfully compromised its official software distribution system, using the company’s OP1w 4K V2 mouse configuration tool to spread dangerous Xred malware to unsuspecting customers for nearly two weeks. The security breach, which occurred between June 26 and July 9, 2025, represents a troubling example of supply […]

Score
69
Read more
4

From Friction to Function: Optimising Onboarding in an Age of AML, AI and Rising Risk

Finextra Security • 7 hours ago

From Friction to Function: Optimising Onboarding in an Age of AML, AI and Rising Risk Join this webinar, hosted in association with nCino, to the challenges of commercial onboarding, particularly in the context of increasing regulations like the EU AML Directive and an emphasis on the importance of data strategy, AI, and streamlining Client Lifecycle Management (CLM). How can banks scale AML compliance in an increasingly complex and high-risk environment without compromising the commercial clien

Score
68
Read more
5

Microsoft Patches ‘ToolShell’ Zero-Days Exploited to Hack SharePoint Servers

SecurityWeek • 5 days ago

Microsoft has started releasing updates to fix the exploited SharePoint zero-days tracked as CVE-2025-53770 and CVE-2025-53771.

Score
68
Read more

Save to Folder

Choose a folder to save this article:

Article Intelligence

Key entities and indicators for this article

DOMAINS
npmjs.com
npnjs.com
webhook.site
ATTACK TYPES
Credential Theft
Data Exfiltration
Phishing
Typosquatting
COMPANIES
GitHub
PLATFORMS
Windows
RANSOMWARE
First
One
core
global
MITRE ATT&CK
Phishing
Screen Capture
DOMAINS
webhook.site
npnjs.com
npmjs.com
ARTICLE INFORMATION
Article #4946
Published 1 day ago
Ars Technica