Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: supply-chain (128 articles)Clear

AI agent swarm abused RubyGems and got code execution on RubyDoc servers

Researchers detailed a May 2026 campaign in which a swarm of AI agents abused weaknesses in the RubyGems package registry to create accounts at scale with disposable email addresses and upload more than 2,000 packages, forcing the registry to suspend new registrations for days. The agents then leveraged the documentation builder on RubyDoc.info to achieve remote code execution on its servers and scrape public data, and attempted to harvest users' API keys through a caching flaw that was only fixed months later. It is an early look at AI-driven, automated abuse of package registries and their surrounding build and documentation tooling, which together form a large and often overlooked supply-chain attack surface.

Check
Harden package-registry registration against automated abuse with rate limits and verified emails, sandbox documentation and build pipelines that process untrusted packages, and monitor for mass account creation and package uploads.
Affected
Package registries and their documentation or build tooling that process untrusted packages; weak registration enables mass automated account creation, and build or doc services can be pushed into code execution.
Fix
Enforce strong registration and rate limits, isolate build and documentation services from sensitive systems, patch known abuse paths promptly, monitor for anomalous automated activity, and treat registry-adjacent tooling as attack surface.

Shai-Hulud npm worm now hunts credentials across 469 different locations

Researchers at GitGuardian found that a recent variant of the self-spreading Shai-Hulud npm worm has expanded its credential theft to scan 469 distinct locations on infected developer machines. The targets now span developer environments, continuous integration and deployment tooling, cloud configuration files, and even the configuration of AI tools. That breadth turns a single compromised package into a wide net for secrets, from cloud and registry credentials to keys held by developer and AI tooling. It reflects how supply-chain worms are industrializing secret collection, treating any credential a developer's machine can reach as fair game once malicious code runs during installation or use.

Check
Scan your dependencies and lockfiles for known-compromised packages, rotate any credentials that a developer machine or pipeline can reach, and reduce the number of long-lived secrets stored in reachable configuration files.
Affected
Developers and CI/CD systems that install compromised npm packages; the worm harvests credentials from 469 locations across developer, pipeline, cloud, and AI-tool configurations, then uses them to spread and steal further secrets.
Fix
Pin and vet dependencies, use scoped short-lived tokens instead of long-lived secrets, isolate build environments, monitor for credential access during installs, and keep secrets out of files developer and AI tools read.

BGP hijack poisons a server-panel update to plant persistent root access

Attackers used a BGP hijack, a manipulation of internet routing, to divert update traffic for Virtualizor, a widely used server and hypervisor management panel, to a server they controlled. During the diversion, which began August 28, they obtained a valid TLS certificate so the connection looked legitimate, then delivered a malicious update that installed persistent root access on affected hosts. One hosting provider found root-level compromise on five of thirty-four hypervisors it checked. Because the software's updates were not cryptographically signed, transport encryption alone did not stop the tampering once routing was hijacked. The vendor released a scanner and patch, but package signing remains unfinished, leaving update integrity dependent on routing security.

Check
Run the vendor's scanner on Virtualizor hosts, check for the published indicators like the malicious service and payload file, rotate and IP-restrict API keys, and audit for unknown SSH keys and users.
Affected
Hosting providers and organizations running Virtualizor that pulled updates during the hijack window; a malicious signed-looking update could install persistent root access on hypervisors, exposing every virtual machine they host.
Fix
Scan and remediate affected hosts preserving evidence, rotate credentials and API keys, verify update integrity independently of transport encryption, monitor routing for hijacks of critical vendors, and prefer vendors that sign updates.

Attackers exploit a critical JFrog Artifactory flaw to mint admin tokens

Days after disclosure, attackers are exploiting a critical authentication-bypass flaw in JFrog Artifactory, the widely used repository manager for binaries, packages, containers, and build artifacts. Tracked as CVE-2026-82329 and scored 9.8, the flaw lets an unauthenticated attacker with network access gain administrative privileges under Artifactory's default configuration. Researchers at watchTowr observed exploitation beginning September 1, with attackers minting admin tokens for themselves and enumerating users, groups, and credentials. Because Artifactory sits at the center of software supply chains and CI/CD pipelines, admin access lets attackers tamper with build pipelines, poison trusted dependencies, and push malicious code downstream to customers. JFrog patched it in version 7.161.20 on August 28.

Check
Patch self-managed JFrog Artifactory to 7.161.20 or later immediately, prioritizing internet-exposed instances, then inspect audit logs for unexpected admin tokens, user enumeration, and any changes to hosted artifacts.
Affected
Organizations running self-managed JFrog Artifactory in default configuration (CVE-2026-82329); an unauthenticated attacker with network access can gain admin, mint tokens, harvest credentials, and tamper with the supply chain, and exploitation is active.
Fix
Patch now, rotate Artifactory credentials and tokens, review hosted packages and build pipelines for tampering, restrict network exposure of the service, and treat any exposed unpatched instance as a supply-chain compromise.

Trusted browser extensions turned into crypto stealers through ownership handoffs

Researchers at Socket detailed a long-running campaign, active since early 2024, in which Chrome and Edge extensions delivered an extensible malware framework of sixteen modules to steal cryptocurrency, credentials, session tokens, and browsing data, and to inject ClickFix lures. Notably, several extensions started out legitimate and were only weaponized later, after their original developers handed over control and new owners pushed malicious automatic updates. One extension reached seventy thousand users before removal. The malware ran from the extension's background worker, opened an encrypted connection to its servers, and displayed fake wallet-recovery pages on real crypto sites to capture recovery phrases.

Check
Audit installed Chrome and Edge extensions, remove unneeded ones, and recognize that a once-safe extension can turn malicious through an update after its ownership changes, silently and without a new prompt.
Affected
Users of the affected Chrome and Edge extensions, especially crypto holders; the framework steals wallet recovery phrases, credentials, session cookies, and browsing data, and can prompt users into running attacker commands.
Fix
Restrict extension installs through browser policy, review extension permissions, keep crypto wallets off browsers used for general work, monitor for the campaign's indicators, and move funds if a compromised extension was installed.

China-made ZBT routers ship with factory backdoors granting unauthenticated root

Researchers at VulnCheck found two undocumented factory implants in the firmware of routers made by the Chinese manufacturer ZBT, each giving a remote, unauthenticated attacker the ability to run commands as root. Named SPEAKINGSTONE and DARKLANTERN and tracked as CVE-2026-74232 and CVE-2026-74233, both scored around 9.3, require no privileges or interaction. SPEAKINGSTONE runs as a hidden service and beacons out over a fixed UDP port to a hardcoded command-and-control server; because it dials outward, it works from behind network address translation and normal egress filtering. The findings underscore the supply-chain risk of low-cost networking hardware with opaque firmware.

Check
Identify any ZBT or Zbtlink routers in your environment, isolate or replace affected models, and block outbound traffic to the implant's command-and-control server and its fixed UDP port.
Affected
Anyone operating affected ZBT-manufactured routers, including rebranded models; the built-in implants let a remote unauthenticated attacker gain root, and one beacons out to a hardcoded server, working even from behind NAT.
Fix
Replace untrustworthy OEM networking gear, segment and monitor such devices, block known implant command-and-control destinations, inspect egress for beaconing on the implicated port, and prefer vendors with transparent, verifiable firmware.

First car head unit malware spreads through built-in Android updaters

Kaspersky documented what it calls the first malware found on a car head unit with an infection chain built specifically for that kind of device. The malware spreads through the built-in software updaters of certain Android-based automotive head unit firmware, then pulls a multi-stage downloader that runs ad fraud and enrolls the unit into a reverse-proxy botnet. Researchers attribute it with high confidence to a group tied to the BADBOX ad-fraud and residential-proxy operation. A head unit is the central console that handles media and, on many vehicles, some vehicle functions, so malware delivered through its own update mechanism is a notable expansion of automotive supply-chain risk.

Check
For fleets and connected-vehicle programs, ask head unit and firmware suppliers about the integrity of their built-in updaters, and monitor automotive and IoT devices for proxy or ad-fraud traffic.
Affected
Vehicles using affected Android automotive head unit firmware whose built-in updater delivered the malware; infected units run ad fraud and act as reverse-proxy nodes, and the head unit has partial vehicle-function access.
Fix
Treat the firmware update channel as a supply-chain trust boundary, source head units from vendors with signed verified updates, monitor connected vehicles for anomalous outbound traffic, and track this actor's proxy infrastructure.

Fake npm calendar tools drop an AI-assisted Linux backdoor on import

Trend Micro found 14 malicious npm packages that pose as working calendar and streak utilities while secretly installing a Linux backdoor from the commercial RedC2 4.0 toolkit. The packages function as advertised, but on load they locate a bundled binary disguised as a math accelerator, mark it executable, and run it as a detached background process. No install script is needed, so a single import anywhere in the dependency graph, even a transitive one, triggers execution. RedC2 is sold on criminal forums as an evasion-focused command-and-control framework with surveillance, credential theft, tunneling, in-memory payload execution, and AI-assisted command features. It shows how import-time execution keeps making package registries an easy delivery route.

Check
Audit npm dependencies, including transitive ones, for the malicious calendar packages and any bundled binaries, and remove them, since simply importing one runs the backdoor without an install script.
Affected
Developers and systems that installed the trojanized npm calendar packages; importing one anywhere in the dependency tree drops and runs a RedC2 Linux backdoor with surveillance, credential theft, and remote-control capabilities.
Fix
Pin and vet dependencies, watch for packages that bundle binaries or spawn detached processes on import, use lockfiles and isolated builds, and monitor developer and CI hosts for unexpected outbound connections.

US Bank ties ransomware leak claim to a fourth-party vendor incident

US Bank said that data-theft claims made by the LockBit ransomware group stem from a fourth-party incident that happened outside its own environment, at a contractor working for one of its third-party vendors. The bank stated there is no evidence its own systems, networks, or data repositories were compromised, while LockBit set a deadline to leak the data unless paid. The "fourth-party" framing is the notable part: exposure reached the bank's customers through a vendor's vendor, two steps removed from its own controls. It follows earlier third-party incidents affecting US Bank customer data and underscores how far organizations' real attack surface extends beyond their direct suppliers.

Check
Map not just your direct vendors but their subcontractors, and require contractual security and breach-notification obligations that flow down to fourth parties handling your data.
Affected
Organizations whose data is handled by vendors' subcontractors; a breach at a fourth party can expose customer data even when your own and your direct vendor's systems are untouched.
Fix
Extend third-party risk management to fourth parties, inventory where data flows downstream, require flow-down security terms and prompt breach notification, and remember that paying extortion does not guarantee stolen data is deleted.

Poisoned Rust crate ran malware at build time inside a 245-million-download library

Attackers briefly poisoned arrayref, a foundational Rust crate with about 245 million downloads that sits underneath widely used graphics and blockchain libraries, along with two sibling crates from the same maintainer account. The crate code itself was clean; each added a dependency on a typosquat of a popular package whose build script ran during compilation, pulling and executing an infostealer that grabbed host data and browser credentials. Because the malicious code lived in a build script, simply compiling a project that resolved the crate ran it, with nothing from the library needing to be called. The bad versions were pulled within about ninety minutes, but any build during that window was exposed.

Check
If you build Rust projects, check whether arrayref, internment, or append-only-vec resolved during the exposure window, search the Cargo cache for the malicious files, and pin arrayref to 0.3.9 or earlier.
Affected
Rust developers and CI systems that resolved the poisoned crate versions during the window; the malicious build script ran an infostealer at compile time, taking host information and browser credentials.
Fix
Build with committed lockfiles and the locked flag to avoid pulling fresh malicious versions, enable two-factor authentication on registry accounts, and treat any machine that built during the window as potentially compromised.