Coordinated Supply Chain Attack Targets Linux Developers via SSH Malware
Article Content
- •Malware is disguised under SSH-like filenames during software installation.
- •Attack targets developers through hidden scripts in package.json files.
- •Ongoing campaign affecting numerous software projects on platforms like GitHub.
Hackers have launched a supply chain attack targeting developers by embedding a malicious Linux payload disguised under an SSH-like filename during software installation. The attack utilizes a hidden post-install script within package.json, allowing the malware to evade detection. This method is particularly insidious as it exploits common developer practices, making it difficult to identify during routine checks. The malicious script downloads a Linux binary that masquerades as a standard system process. Developers using platforms like GitHub are primarily affected, with the scope of the attack potentially impacting numerous projects. Security experts are urging immediate vigilance and review of software dependencies to mitigate risks. Current status indicates that the attack is ongoing, with no specific remediation steps detailed yet.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Massive Network of AI Proxy Servers Used for Malicious Activities Uncovered Security researchers from Team Cymru have identified over 10,000 proxy servers in China facilitating malicious AI activities. These servers, termed 'transfer stations,' are primarily used to bypass geographic restrictions and conduct model distillation attacks against frontier AI models. The infrastructure allows…
Critical RCE Vulnerability in F5 BIG-IP APM Exploited in the Wild A severe heap-based buffer overflow vulnerability, tracked as CVE-2026-94127, has been identified in F5 BIG-IP Access Policy Manager (APM), allowing unauthenticated remote code execution (RCE) on the Traffic Management Microkernel (TMM) data plane. This vulnerability is triggered when both an APM access policy and an…