WhisperX tag archive

#supply_chain_attack

This page collects WhisperX intelligence signals tagged #supply_chain_attack. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (5)

The Lab · 2026-04-16 06:22:51 · GitHub Issues

1. Aqua Security Trivy Supply Chain Attack: Malicious Releases & Credential-Stealing Tags Force-Pushed to GitHub Actions

A sophisticated supply chain attack has compromised the core security tools of Aqua Security's Trivy project, with a threat actor using stolen credentials to publish malicious software releases and force-push dozens of version tags to credential-stealing malware. The attack targeted the `aquasecurity/trivy-action` GitH...

The Lab · 2026-04-19 20:52:27 · The Verge

2. Vercel Hacked: ShinyHunters Group Claims Breach, Sells Stolen Developer Data

The cloud development platform Vercel has been compromised, with hackers linked to the notorious ShinyHunters group attempting to sell stolen data. The breach, which Vercel has confirmed as a 'security incident,' exposed sensitive information including employee names, email addresses, and activity timestamps. This atta...

The Lab · 2026-05-12 04:48:18 · Hacker News

3. npm Supply Chain Attack Exposes 170+ Packages Including TanStack and Mistral AI—Maintainer Accounts Left Uncompromised

A sweeping npm supply chain attack has surfaced, targeting more than 170 packages with over 400 malicious versions published. The campaign stands out for a critical anomaly: investigators found no evidence that any maintainer accounts were compromised, raising sharp questions about how the malicious code entered the ec...

The Lab · 2026-05-12 12:48:29 · The Register

4. TanStack npm Supply Chain Breach: 84 Malicious Packages Deployed in Six Minutes, Disk-Wiping Malware Confirmed

A sophisticated supply chain attack compromised 84 versions of TanStack npm packages between 19:20 and 19:26 UTC on May 11, embedding malware capable of credential theft, self-propagation, and complete disk erasure on infected hosts. The campaign, linked to the ongoing Mini Shai-Hulud operation, also targeted packages ...

The Lab · 2026-05-12 13:18:33 · Mastodon:mastodon.social:#cybersecurity

5. Shai-Hulud Attack Exposes Tanstack Ecosystem: 80+ npm Packages Backdoored in Supply Chain Breach

Security researchers at Endor Labs have uncovered a sophisticated supply chain attack dubbed "Shai-Hulud," which has compromised over 80 packages within the Tanstack ecosystem. The attack represents a significant intrusion into one of JavaScript's most widely used developer frameworks, raising alarms across the open-so...