Netcrook Logo

Tag: Supply Chain Attack

219 article(s)

Vimeo Data Breach: ShinyHunters Exploit Anodot in Major Supply Chain Attack

28 Apr 2026 news 🌍 North America

Vimeo has confirmed that user data was exposed after a cybercrime group breached its analytics provider Anodot. The ShinyHunters gang is demanding ransom, highlighting the dangers of supply-chain attacks affecting major platforms.

#Vimeo | #ShinyHunters | #supply chain attack

Checkmarx GitHub Breach: How a Supply Chain Hack Fueled a Dark Web Leak

28 Apr 2026 news

Checkmarx confirmed a major breach after LAPSUS$ hackers leaked internal GitHub repository data on the dark web, exposing the hidden dangers of supply chain attacks. Here’s what happened and why it matters.

#Checkmarx | #LAPSUS$ | #Supply Chain Attack

Zero Trust, Zero Mercy: When Cybersecurity Vendors Become the Target

28 Apr 2026 news

As ransomware gangs increasingly target cybersecurity vendors, the risks to customers and the entire digital ecosystem multiply. This feature investigates the new frontline of cybercrime and what it means for trust in the security industry.

#Ransomware | #Cybersecurity Vendors | #Supply Chain Attack

Shadow Code: Checkmarx Source Code and Secrets Leak After Supply Chain Hack

27 Apr 2026 news 🌍 Middle-East

Checkmarx is investigating after hackers leaked its GitHub repository data—including source code and credentials—on the dark web following a major supply chain attack. The breach exposes the dangers of compromised developer tools and the ripple effect across the software ecosystem.

#Checkmarx | #Supply Chain Attack | #Dark Web

Popular Python Package Hijacked: Credential Theft Hits Over a Million Users

27 Apr 2026 news

A major open-source data tool with over a million monthly downloads was weaponized overnight, leaking sensitive credentials and crypto wallets via a sophisticated supply chain attack. Here’s how it happened and what you need to know.

#Python Package | #Supply Chain Attack | #Credential Theft

Namastex npm Worm: Supply Chain Malware Hits AI Developer Packages

27 Apr 2026 news

A new malware campaign has compromised trusted Namastex Labs packages on npm and PyPI, stealing sensitive secrets and spreading through worm-like propagation. The attack, linked to TeamPCP, highlights the growing threat of supply chain attacks in open source.

#Supply Chain Attack | #Malware Campaign | #Open-Source Security

Bitwarden CLI Supply Chain Attack: Malicious Update Steals Developer Secrets

24 Apr 2026 news

A malicious version of Bitwarden CLI was distributed via npm, enabling attackers to steal credentials from developers and CI/CD pipelines. The breach highlights growing risks in software supply chains and the need for rapid incident response.

#Bitwarden | #Supply Chain Attack | #Credential Exfiltration

TeamPCP Exploits Bitwarden CLI and Dependabot in Shai-Hulud Malware Supply Chain Attack

24 Apr 2026 news

A trusted GitHub automation and a popular open-source password manager became the perfect storm for TeamPCP’s Shai-Hulud malware campaign, stealing credentials and poisoning AI coding tools from inside the developer supply chain.

#TeamPCP | #Supply Chain Attack | #Bitwarden

Bitwarden CLI Breach: Dune-Themed Hackers Exploit GitHub Actions in Sophisticated Supply Chain Attack

24 Apr 2026 news

A dramatic supply chain attack hit Bitwarden CLI’s npm package, using GitHub Actions to inject credential-stealing malware and exfiltrate secrets to Dune-themed public repositories. Here’s how it happened and what it means for open source security.

#Bitwarden | #supply chain attack | #GitHub Actions

Bitwarden CLI Breach: GitHub Actions Used in Dune-Themed Supply Chain Attack

24 Apr 2026 news

Attackers exploited Bitwarden’s CI/CD pipeline with a rogue GitHub Action, injecting malware into the @bitwarden/cli npm package. The breach harvests credentials and exfiltrates them through Dune-themed public repositories, highlighting new risks in software supply chains.

#Bitwarden | #Supply Chain Attack | #Credential Harvesting