ZCyberNews
中文

#supply-chain-attack

18 articles

This archive collects 24 articles tagged supply-chain-attack published between April 13, 2026 and May 14, 2026, giving security teams a focused view of how this topic has appeared across ZCyberNews coverage. Observed actor references include GlassWorm, TeamPCP, and APT37, presented only where the underlying article metadata supports the attribution. The affected-scope signals emphasize technology, software development, and cybersecurity across Global, China, and South korea, helping readers compare exposure patterns without adding claims beyond the archive data. Severity coverage includes 7 critical, and 17 high reports.

OpenAI Breached in TanStack Supply Chain AttackHIGH
Industry News

OpenAI Breached in TanStack Supply Chain Attack

OpenAI says two employees' devices were compromised in the TeamPCP Mini Shai-Hulud campaign, forcing rotation of code-signing certificates across macOS, Windows, iOS, and Android.

3 min readTeamPCP
OceanLotus APT Uses PyPI Packages to Deliver ZiChatBot MalwareHIGH
Malware

OceanLotus APT Uses PyPI Packages to Deliver ZiChatBot Malware

Kaspersky attributes a PyPI supply chain campaign to OceanLotus APT, using fake wheel packages to drop ZiChatBot malware that abuses Zulip chat APIs for C2 on Windows and Linux.

4 min readOceanLotus
Quasar Linux RAT Targets Developers for Supply Chain AttacksHIGH
Malware

Quasar Linux RAT Targets Developers for Supply Chain Attacks

A new Linux implant codenamed QLNX steals developer credentials, keystrokes, and clipboard data. Targets DevOps environments for software supply chain compromise.

3 min readQuasar Linux RAT
ZiChatBot Malware Spreads via PyPI Packages Using Zulip C2HIGH
Malware

ZiChatBot Malware Spreads via PyPI Packages Using Zulip C2

Three PyPI packages deliver ZiChatBot malware on Windows and Linux using Zulip chat APIs for stealthy C2 — Kaspersky identifies 12+ victim organizations globally.

4 min readZiChatBot
APT37 Targets Ethnic Koreans in China With Android BirdCall MalwareHIGH
Malware

APT37 Targets Ethnic Koreans in China With Android BirdCall Malware

ESET says APT37 compromised Sqgame card game platform to deliver BirdCall backdoor to Android devices, stealing SMS, call logs, and private keys from ethnic Koreans in Yanbian.

4 min readAPT37
Trellix Source Code Breach Exposes Security Product InternalsHIGH
Industry News

Trellix Source Code Breach Exposes Security Product Internals

Attackers stole source code from Trellix, exposing detection logic and control locations in its security products. The breach amplifies supply chain risks for enterprise customers.

2 min read
Poisoned Ruby Gems, Go Modules Hijack CI/CD PipelinesHIGH
Malware

Poisoned Ruby Gems, Go Modules Hijack CI/CD Pipelines

BufferZoneCorp account published malicious Ruby gems and Go modules that steal credentials, tamper with GitHub Actions, and establish SSH persistence in CI pipelines.

2 min readBufferZoneCorp
Mini Shai-Hulud Attack Hijacks SAP, Lightning, Intercom PackagesCRITICAL
Malware

Mini Shai-Hulud Attack Hijacks SAP, Lightning, Intercom Packages

Attackers compromised SAP, Lightning, and Intercom npm packages in a supply chain attack affecting 1,800 victims; packages had 10M monthly downloads.

2 min readMini Shai-Hulud
AI Browser Extensions Steal Emails, Passwords via Prompt InjectionHIGH
Threat Intel

AI Browser Extensions Steal Emails, Passwords via Prompt Injection

Unit 42 finds 30+ malicious AI browser extensions exfiltrating email content, credentials, and API keys via prompt injection and DOM scraping. Affects Chrome, Edge users.

3 min read
SAP npm Packages Hijacked in Credential-Stealing Supply Chain AttackCRITICAL
Malware

SAP npm Packages Hijacked in Credential-Stealing Supply Chain Attack

Attackers compromised multiple SAP-related npm packages to deploy credential-stealing malware, targeting SAP BTP and cloud app credentials. Campaign dubbed mini Shai-Hulud.

3 min readmini Shai-Hulud
73 Fake VS Code Extensions Deliver GlassWorm v2 Info-StealerHIGH
Malware

73 Fake VS Code Extensions Deliver GlassWorm v2 Info-Stealer

Researchers found 73 cloned VS Code extensions on Open VSX, with 6 confirmed malicious, delivering the GlassWorm v2 info-stealer.

2 min readGlassWorm
Checkmarx Confirms GitHub Data Leak After March 23 Supply Chain AttackHIGH
Industry News

Checkmarx Confirms GitHub Data Leak After March 23 Supply Chain Attack

Checkmarx confirmed a cybercriminal group published GitHub repository data on the dark web, traced to a March 23 supply chain attack.

2 min read
Fast16 Malware Resurfaces in Supply Chain Attacks Abusing TrustedHIGH
Malware

Fast16 Malware Resurfaces in Supply Chain Attacks Abusing Trusted

Fast16 malware resurfaces in new supply chain attacks, abusing remote monitoring tools and browser extensions to steal credentials. Campaign targets enterprise environments.

2 min readFast16
GlassWorm Malware Returns via 73 OpenVSX Sleeper ExtensionsHIGH
Malware

GlassWorm Malware Returns via 73 OpenVSX Sleeper Extensions

A new GlassWorm campaign deploys 73 sleeper extensions on OpenVSX that activate malicious behavior post-update, targeting VS Code users in dev environments.

2 min readGlassWorm
TeamPCP Partners with Vect Ransomware in Supply Chain AttacksCRITICAL
Threat Intel

TeamPCP Partners with Vect Ransomware in Supply Chain Attacks

Unit 42 reports TeamPCP has partnered with Vect ransomware group to target security software vendors in multi-stage supply chain attacks, compromising trusted update mechanisms.

2 min readTeamPCP
Bitwarden CLI Compromised in Checkmarx Supply Chain AttackCRITICAL
Malware

Bitwarden CLI Compromised in Checkmarx Supply Chain Attack

JFrog and Socket found malicious code in @bitwarden/[email protected] — the same campaign that hijacked Checkmarx npm packages.

3 min read
Bitwarden CLI npm Package Hijacked to Steal Developer CredentialsCRITICAL
Threat Intel

Bitwarden CLI npm Package Hijacked to Steal Developer Credentials

Attackers published a malicious @bitwarden/cli npm package that steals credentials and spreads to other projects.

2 min read
WordPress Supply Chain Attack Infects 30+ Plugins Planted Malicous Backdoor CRITICAL
Threat Intel

WordPress Supply Chain Attack Infects 30+ Plugins Planted Malicous Backdoor

A malicious buyer used the Flippa marketplace to acquire a plugin developer, injecting a backdoor into over 30 WordPress plugins with hundreds of thousands of installations to deploy hidden SEO spam.

6 min read

Stay Updated

Get the latest cybersecurity news delivered to your inbox.