WhisperX tag archive

#credential_theft

This page collects WhisperX intelligence signals tagged #credential_theft. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Lab · 2026-04-16 06:22:51 · GitHub Issues

1. Aqua Security Trivy Supply Chain Attack: Malicious Releases & Credential-Stealing Tags Force-Pushed to GitHub Actions

A sophisticated supply chain attack has compromised the core security tools of Aqua Security's Trivy project, with a threat actor using stolen credentials to publish malicious software releases and force-push dozens of version tags to credential-stealing malware. The attack targeted the `aquasecurity/trivy-action` GitH...

The Lab · 2026-05-12 12:48:29 · The Register

2. TanStack npm Supply Chain Breach: 84 Malicious Packages Deployed in Six Minutes, Disk-Wiping Malware Confirmed

A sophisticated supply chain attack compromised 84 versions of TanStack npm packages between 19:20 and 19:26 UTC on May 11, embedding malware capable of credential theft, self-propagation, and complete disk erasure on infected hosts. The campaign, linked to the ongoing Mini Shai-Hulud operation, also targeted packages ...