Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: supply-chain (128 articles)Clear

Bitget says attacker used third party security product flaw to steal 388 million dollars

Cryptocurrency exchange Bitget said the attacker who stole about 388 million dollars gained access through a vulnerability in a third-party security product the exchange used. The attacker exploited the flaw to obtain high-level internal credentials, then on September 24 used them to reach an internal management system and insert fraudulent withdrawal commands into wallet backend services, where they were treated as legitimate. The stolen funds came from Bitget's hot and warm wallets, while its offline cold wallets were unaffected. CEO Gracy Chen described the incident publicly, confirming the earlier statement that a critical wallet backend system had been compromised and used to spoof transaction data and trigger approvals.

Check
Review third-party security products in privileged positions for patch status and blast radius, and treat their credentials as high-value targets requiring isolation.
Affected
Organizations relying on a vulnerable third-party security product can have its high-level credentials stolen and abused to command core backend systems.
Fix
Inventory and patch third-party security tooling, scope its access tightly, add out-of-band approval for high-value transfers, and monitor for anomalous internal commands.

Popular Chrome ad blocker extensions disclose selling users' browsing data to third parties

LayerX research found dozens of Chrome extensions, reaching millions of users, that legally sell or share user data under terms accepted at install. Among ad blockers, it confirmed eight reserving the right to sell or share user information, together reaching over 5.5 million users. Stands AdBlocker, with three million users, sells browsing data for market analytics, and Poper Blocker, with two million users, discloses selling identifiers, browsing activity, and behavioral profiles inferred from visited URLs. Smaller ad blockers route browsing data and even AI conversations through data brokers. The finding shows tools installed to stop tracking can themselves become data exfiltration channels, a browser extension supply chain risk static malware scanning misses.

Check
Inventory browser extensions across managed fleets, remove data-selling ad blockers like the named ones, and enforce an allowlist for permitted extensions.
Affected
Users who installed these ad blockers consented in the terms to having their browsing data, identifiers, and inferred profiles sold or shared with third parties.
Fix
Deploy an enterprise extension allowlist, review extension permissions and privacy terms, and educate users that ad blockers can monetize their data.

Compromised GitHub Actions came back online still executing Mini Shai-Hulud credential malware

Socket reported that two GitHub Actions, actions-cool/issues-helper and actions-cool/maintain-one-comment, were disabled a second time after their repositories became accessible again on September 16, months after being compromised in the May Mini Shai-Hulud campaign. When the repositories returned, their release tags were not cleaned up and still pointed to the malicious content introduced on May 18, so any workflow referencing either action by a version tag resumed downloading and executing the payload on its next run. The original May 18 compromise ran code that harvested credentials from CI/CD pipelines and exfiltrated them, activity linked to the Mini Shai-Hulud cluster through a shared exfiltration domain. GitHub has again disabled both repositories.

Check
Audit workflows for references to the two actions-cool actions, pin actions to trusted commit hashes, and rotate any CI/CD secrets exposed since September 16.
Affected
Pipelines referencing the affected actions-cool actions by version tag re-ran the May 18 payload after September 16, harvesting and exfiltrating CI/CD credentials.
Fix
Remove or repin the actions to vetted commits, rotate pipeline secrets, and prefer commit-hash pinning over mutable version tags for third-party actions.

Attackers plant Go malware in HashiCorp Terraform registry in first such supply chain abuse

Aikido disclosed Go-based malware distributed through two Go modules and two Terraform providers, the first time attackers have used HashiCorp's centralized registry as a distribution vector. The flagged items include kreuzwenker/docker, with 1,449 downloads, and gocommunity-io/dockerd, alongside two Go modules. The malware overlaps with the Graphalgo campaign that ReversingLabs attributed to North Korean actors in February, in which developers are approached on LinkedIn, Facebook, or job forums by fake Web3 companies and asked to run a benign repository that pulls the malicious behavior from a dependency. The discovery coincides with a fresh batch of malicious npm and PyPI packages delivering the same threat, flagged by Checkmarx, JFrog, and SafeDep.

Check
Vet Terraform providers and Go modules by publisher and source, pin and review versions, and scan developer machines for the flagged packages and modules.
Affected
Developers pulling the malicious Terraform providers or Go modules, or the paired npm and PyPI packages, execute Go malware tied to the Graphalgo campaign.
Fix
Restrict registries to vetted providers, enforce allowlists for infrastructure-as-code sources, and treat unsolicited coding tasks from recruiters as supply chain risk.

Malicious npm package impersonates Twilio bug bounty probe to exfiltrate developer credentials

ReversingLabs detailed a malicious npm package, tw-pkgprobe-7731, that masquerades as an authorized Twilio bug-bounty research probe while harvesting developer data. Uploaded in mid-August by an account that no longer exists, it shipped eleven versions within about 45 minutes. Comments inside describe it as an authorized HackerOne probe that runs only inside Twilio's serverless sandbox and takes no destructive action. On execution it first checks for a Twilio developer environment and exits otherwise, then collects environment variables plus system details like mounts and temporary folders and exfiltrates them through a webhook. Later versions specifically target developers using Twilio APIs by searching for folders tied to particular Twilio account identifiers, sharpening the credential theft.

Check
Block and audit for tw-pkgprobe-7731 across developer and build environments, then rotate Twilio credentials and API keys exposed on any affected machine.
Affected
Developers integrating Twilio who installed the package inside a matching environment had environment variables and account-linked configuration harvested and sent to an attacker webhook.
Fix
Pin and vet npm dependencies, alert on packages that fingerprint the environment before acting, and restrict outbound webhooks from build and developer hosts.

Malicious npm package hides loader in runtime method to bypass install script controls

Checkmarx found an ongoing npm campaign built around indexed-btree, a package impersonating the popular sorted-btree library that has amassed two million weekly downloads. Instead of using preinstall or postinstall scripts, the malware hides its loader inside the BTree.prototype.set method that applications call constantly, so it executes at runtime rather than install time. This sidesteps the npm approval gates GitHub added in June to block lifecycle scripts, and installation looks clean to static scanners. Once triggered, it fingerprints the host, exfiltrates details over hardcoded Slack and Telegram channels, and polls an Ethereum Sepolia smart contract for encrypted second-stage commands.

Check
Audit dependency trees for indexed-btree and typosquats of sorted-btree, then remove them and rotate any credentials exposed to affected build or runtime hosts.
Affected
Projects that installed indexed-btree run the loader the first time application code calls the tree, giving attackers host fingerprinting and staged command execution.
Fix
Pin dependencies to reviewed versions, scan for runtime-triggered loaders not just install scripts, and block outbound Slack, Telegram, and testnet RPC from build hosts.

Researchers escape OpenAI Codex sandbox to run commands on developer machines

Accomplish AI researcher Oren Yomtov disclosed two OpenAI Codex sandbox escapes, the more serious dubbed Heapjack. Codex Desktop installs a node_repl component into the global config with no opt-in, and plain Codex CLI users inherit it. That process runs trusted OpenAI code and untrusted agent code in one Node instance sharing a heap, where a random authorization token sits in memory. Untrusted code snapshots the heap, recovers the token, and writes requests onto the pipe to an unsandboxed parent process, reaching any Unix socket including a Docker daemon. Opening a malicious repository and asking about the code yields unsandboxed execution with no prompt.

Check
Update Codex CLI and Desktop to the fixed builds, then review whether developers opened untrusted repositories in Codex during the exposure window.
Affected
Any Codex user, including CLI users who never enabled it, could be handed host command execution by opening someone else's repository and querying it.
Fix
Apply OpenAI's patches, isolate coding agents from Docker sockets and credentials, and treat opening untrusted repositories in an agent as code execution.

Flaw lets repository owners swap pinned plugin code across four AI coding agents

Air Security reported that four AI coding agents fetch plugins pinned to a reviewed commit hash but never verify the code they receive matches it. On code hosts that permit branch names shaped like commit hashes, such as Bitbucket or self-hosted git, a plugin repository owner can point that name at different code, so the agent installs malicious code while reporting the locked version. Because plugins run with the user's access, the swapped code reaches files, credentials, and connected systems. Anthropic fixed it in Claude Code 2.1.179 and OpenAI in Codex 0.146.0; GitHub Copilot has no fix, and Google will not patch the retiring Gemini CLI.

Check
Update Claude Code and Codex to the fixed releases, then inventory installed agent plugins sourced from Bitbucket or self-hosted git rather than GitHub.
Affected
Agents installing plugins from hosts that allow commit-hash-shaped branch names can run attacker-swapped code under the user's own access despite version pinning.
Fix
Upgrade to patched agents, restrict plugins to GitHub-hosted repositories that block such branch names, and review Copilot and Gemini CLI plugin usage.

Stolen Cloudflare key let attackers poison Brevo scripts on 100,000 sites

Attackers stole a Cloudflare API key from marketing platform Brevo and used it to inject malicious code into the scripts that Brevo's customers embed on their own websites, affecting more than 100,000 sites. The key was long-lived, had full account permissions, and was hardcoded in application source code, which let the attackers create a Cloudflare Worker that modified Brevo's forms, widget, and loader scripts at the network edge for about five and a half hours. Visitors saw a fake verification page with ClickFix instructions to run a command on Windows, and on WordPress sites where an admin was logged in, the script tried to silently install a backdoor plugin.

Check
Keep API keys out of source code, replace long-lived full-permission keys with scoped short-lived credentials in a secrets manager, and review third-party scripts your sites embed for unexpected changes or injected content.
Affected
Websites embedding Brevo's scripts and their visitors during the incident; a stolen key let attackers modify those trusted scripts at the edge to push ClickFix malware and a WordPress backdoor plugin.
Fix
Scope and rotate API keys, store them outside code, constrain embedded third-party scripts with subresource integrity and content security policy, monitor for edge content changes, and teach users to reject paste-a-command prompts.

Attacker hijacks an AI coding session and spreads Shai-Hulud to 100 repositories

Mandiant reported that an attacker hijacked a developer's active AI coding-assistant session at a software company and used it to spread the self-replicating Shai-Hulud worm across about 100 internal code repositories. The chain started when the AI assistant recommended a piece of software the attacker had poisoned, and the developer accepted the suggestion. Using the live session, the attacker installed an infostealer through a poisoned PyPI package and stole GitHub access tokens, then unleashed the worm, which stole repository secrets and source code. The attacker also poisoned a package in the company's own namespace, so a second developer's pull caused a reinfection. It shows AI-recommended dependencies as a new poisoning path.

Check
Check dependencies that an AI assistant recommends against cryptographic checksums and an approved allowlist before installing them, and keep API keys and long-lived OAuth tokens out of reach of coding-assistant extensions.
Affected
Development teams using AI coding assistants that install dependencies with the developer's credentials; a poisoned recommendation or hijacked session can plant an infostealer, steal tokens, and spread a worm through repositories.
Fix
Route dependency traffic through internal repositories, verify AI-suggested packages before use, scope tokens the assistant can reach, monitor for worm-like package activity, and treat a compromised coding session as a supply-chain incident.