// SUPPLY CHAIN

// SUPPLY CHAIN

4 articles
All Zero-Day Ransomware Phishing Supply Chain AI Security Data Breaches Malware Vulnerabilities Attacks Security
Malicious NuGet Packages Stole ASP.NET Data; npm Package Dropped Malware

Security researchers discovered four malicious NuGet packages designed to steal ASP.NET Identity data including user accounts and permissions, while manipulating authorization rules to create backdoors in victim applications. This represents an active malware campaign targeting ASP.NET developers with real data exfiltration capabilities.

Malicious npm Packages Harvest Crypto Keys, CI Secrets, and API Tokens

Cybersecurity researchers discovered an active supply chain attack campaign using at least 19 malicious npm packages to harvest cryptocurrency keys, CI secrets, and API tokens. The campaign, codenamed SANDWORM_MODE by Socket, represents a real threat targeting developers through compromised package dependencies.

Cline CLI 2.3.0 Supply Chain Attack Installed OpenClaw on Developer Systems

Cline CLI version 2.3.0 was compromised via a stolen npm publish token, allowing an attacker to distribute malicious updates that installed OpenClaw malware on developer systems. This represents an actual supply chain attack affecting real victims in the developer community.

Supply Chain Attack Secretly Installs OpenClaw for Cline Users

A supply chain attack compromised the Cline npm package (version 2.3.0), with the malicious version installing OpenClaw malware and being downloaded over 4,000 times before removal. This represents an actual active malware campaign targeting developers through a legitimate package repository.