Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
TanStack 'Mini Shai-Hulud' Supply Chain Attack: IOC Analysis and macOS Hardening
Introduction OpenAI recently confirmed that two of its corporate macOS devices were compromised during the TanStack supply chain attack, dub...
CVE-2022-23812: node-ipc npm Supply Chain Attack — Detection and Remediation Guide
Introduction A critical supply chain attack has compromised the node-ipc package, a widely used dependency in the JavaScript ecosystem with ...
Supply Chain Attack: Malicious Node-IPC Versions (v9.1.6, v9.2.3, v12.0.1) — Detection and Remediation
Introduction A critical supply chain compromise has been identified within the widely used node-ipc npm package. Security researchers at Soc...
Mini Shai-Hulud: Detecting SAP NPM Supply Chain Attack and Bun Binary Abuse
Introduction The open-source ecosystem faces a persistent threat from supply chain compromises, and the recent "Mini Shai-Hulud" attack camp...
npm Supply Chain Attacks: Detecting Shai Hulud-style Malware and CI/CD Persistence
Introduction The JavaScript ecosystem is currently the battleground for one of the most sophisticated supply chain campaigns we've seen in y...
Bitwarden NPM Package Supply Chain Attack: Detection and Remediation Guide
Bitwarden NPM Package Supply Chain Attack: Detection and Remediation Guide Introduction Bitwarden, a popular password manager, has been impa...
Npm Supply Chain Attack: Worm-Like Propagation and Credential Theft — Detection and Remediation
Introduction A sophisticated supply chain attack targeting the npm registry has been identified, characterized by worm-like propagation capa...
Bitwarden CLI npm Compromise: Detecting Malicious @bitwarden/cli Packages (v2024.8.0, v2024.7.1)
Introduction The software supply chain was struck again when attackers compromised the official Bitwarden CLI npm package, @bitwarden/cli. B...
Axios npm Supply Chain Attack: Emergency Detection and Incident Response for Malicious Versions 1.14.1 and 0.30.4
Introduction A confirmed supply chain attack has compromised the Axios npm package, one of the most widely used HTTP client libraries in the...