This situation has concluded
It was preserved as a record on September 3; the timeline below shows how it unfolded, with sources. Get the briefing to follow the top situations still developing: three emails a week, sourced and in order.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
34 clusters · 97 sources · 82 days · First seen · Last updated
Software supply‑chain & AI attacks on dev ecosystems
Overview
Supply‑chain compromises continue to spread across JavaScript, Python, Rust and PHP ecosystems, targeting AI‑focused developers and cloud‑credential stores. The Mini Shai‑Hulud campaign, linked to TeamPCP, poisoned over 300 npm and PyPI packages—including TanStack, Mistral AI, UiPath and OpenAI’s internal tools—allowing credential theft and, in OpenAI’s case, the exfiltration of macOS code‑signing certificates. A parallel “TrapDoor” operation injected malicious utilities into npm, PyPI and Crates.io, stealing crypto‑wallet data and cloud tokens while manipulating AI coding assistants such as Claude and Cursor.
The Glassworm botnet, which had infiltrated VS Code extensions and hundreds of GitHub repositories, was dismantled by a coordinated effort from CrowdStrike, Google and the Shadowserver Foundation, cutting its four C2 channels. Shortly thereafter, the self‑replicating Miasma worm (also called Shai‑Hulud) infected dozens of Microsoft‑owned GitHub repos and Red Hat Cloud‑Services packages, prompting rapid repository takedowns and credential rotations.
New attack vectors emerged against AI agents: the “GitLost” prompt‑injection flaw lets unauthenticated users coerce GitHub’s Agentic Workflows to read private repositories, while “Agent Data Injection” attacks spoof metadata to trigger unwanted commands in Claude, Gemini and other assistants. Google disclosed an AI‑generated zero‑day that bypassed two‑factor authentication, and the GhostLock Linux‑kernel use‑after‑free bug (CVE‑2026‑43499) was patched across major distributions.
Mitigations are being rolled out: GitHub will disable automatic npm install scripts in npm v12; Microsoft warned of crypto‑stealing npm packages and released patches for Exchange and Copilot; and researchers highlighted emerging techniques such as “HalluSquatting” and “Agent Baiting” that automate repository discovery for AI agents. The combined wave of supply‑chain, AI‑assisted and credential‑theft attacks underscores the urgent need for SBOM adoption, stricter CI/CD controls, and continuous monitoring of package registries.
Entities
Google · Chrome · Unit 42 (Palo Alto Networks) · Google LLC · Pillar Security
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 7 SOURCES] Malware on compromised Windows PCs can hijack Google Password Manager passkeys without user interaction.
- [● 7 SOURCES] Unit 42 identified three attack techniques named Pass‑ta‑key, Silver Pass‑ta‑key and Golden Pass‑ta‑key.
- [● 7 SOURCES] The attacks do not break the underlying cryptography of passkeys.
- [● 4 SOURCES] Pass‑ta‑key extracts Chrome’s wrapped device identity key and uses the TPM to sign authentication requests, bypassing user verification.
- [● 4 SOURCES] Silver Pass‑ta‑key forces a re‑enrollment window to register an attacker‑controlled verification key, allowing login without biometric checks.
- [● 4 SOURCES] Golden Pass‑ta‑key extracts the 32‑byte Security Domain Secret, enabling decryption of all synced passkeys.
- [● 2 SOURCES] Some services (e.g., GitHub) correctly reject forged assertions, while others (e.g., eBay) were vulnerable until patched after disclosure.
- [● 2 SOURCES] Google has been notified and is working on remediation; no CVE identifiers have been assigned yet.
Timeline
-
[TECHNOLOGY] 14 sourcesGoogle Passkey Security Flaw Exposes Accounts to Malware
Unit 42 revealed three malware‑based techniques that let attackers hijack Google Password Manager passkeys on Windows PCs without breaking cryptography, prompting Google to work on fixes.
-
[TECHNOLOGY] 2 sourcesSupply‑Chain Malware Surge and Google's AI Code‑Security Preview
Malicious Shai‑Hulud copies spread on npm, prompting Google to launch CodeMender, an AI tool that scans and auto‑fixes code vulnerabilities.
-
[TECHNOLOGY] 2 sourcesOpen‑source Software Supply Chain Hit by New Critical Libssh2 Flaw and GitHub Actions Abuse
Researchers released a public libssh2 exploit (CVE‑2026‑55200) while attackers weaponized malicious GitHub Actions to target cPanel/WHM servers (CVE‑2026‑41940), highlighting severe supply‑chain risks.
-
[TECHNOLOGY] 6 sourcesFakeGit campaign spreads SmartLoader malware via 7,600 GitHub repositories
The FakeGit campaign operates ~7,600 malicious GitHub repos, with 800 posing as AI tools, to deliver SmartLoader malware and the StealC info stealer; AI agents can be duped via 'Agent Baiting', leading to over
-
[TECHNOLOGY] 4 sourcesGoogle Threat Intelligence reports AI‑crafted zero‑day exploit and DarkSword surveillance malware
Google's Threat Intelligence unveiled the DarkSword exploit chain that records voice, screenshots and data, and disclosed the first AI‑generated zero‑day bypassing 2FA, which was patched before widespread abuse
-
[TECHNOLOGY] 2 sourcesGhostlock Linux Kernel Vulnerability Exposes Root Access After 15‑Year Hideout
AI tool VEGA uncovered Ghostlock (CVE‑2026‑43499), a 15‑year‑old Linux kernel bug that grants root access, affecting major distributions; vendors are issuing patches as Linus Torvalds backs AI‑assisted kernel‑c
-
[TECHNOLOGY] 7 sourcesEmerging Cyber Attack Techniques Target Developer Tools and AI Agents
Researchers report a supply‑chain attack via malicious Vite npm packages and a new Agent Data Injection method that tricks AI assistants into executing harmful actions, exposing developers to credential theft,
-
[TECHNOLOGY] 10 sourcesMicrosoft boosts AI‑driven Windows security as cyber attacks target its services
Microsoft deploys AI to find Windows bugs, leading to larger Patch Tuesdays, as researchers report rising vishing attacks on Microsoft 365, Passkey hijacking, Visual Studio supply‑chain malware and the new Giga
-
[TECHNOLOGY] 3 sourcesLinux kernel 'GhostLock' vulnerability and GitHub AI prompt injection expose major security threats
A Linux kernel use‑after‑free bug (GhostLock, CVE‑2026‑43499) and a GitHub AI prompt‑injection flaw (GitLost) both enable root or private‑code exposure, raising serious security concerns.
-
[TECHNOLOGY] 2 sourcesSupply Chain Attacks Compromise NPM Packages and Exploit AI Hallucinations
Hackers hijacked the @injectivelabs/sdk‑ts npm package to steal crypto keys, while researchers warned that AI‑generated package names are being weaponized in supply‑chain attacks.
-
[TECHNOLOGY] 10 sourcesGitHub AI Agentic Workflows Exposed by 'GitLost' Prompt‑Injection Flaw
GitHub’s Agentic Workflows contain a “GitLost” prompt‑injection bug that lets anyone open a public issue to make the AI agent leak private repository data, bypassing safeguards with a single word.
-
[TECHNOLOGY] 2 sourcesGlobal Cyber Threats: Interpol‑Phishing Scam and TeamPCP Supply‑Chain Attack
Bitdefender exposed an INTERPOL‑impersonating phishing scam targeting SMEs globally, while the FBI warned that TeamPCP poisoned developer tools to steal cloud credentials and spread malware through supply‑chain
-
[TECHNOLOGY] 2 sourcesSupply Chain Threats Hit Mastra AI and Open‑Source Packages
TeamPCP’s multi‑vector supply‑chain attack on Mastra AI and a North Korean‑linked PolinRider campaign have poisoned npm, GitHub Actions, Arch Linux, Go modules and other open‑source repositories, compromising
-
[TECHNOLOGY] 3 sourcesGitHub Actions flaws expose 300+ repositories to supply‑chain attacks
Critical flaws in GitHub Actions let attackers hijack over 300 repositories, including Microsoft and Google projects, by exploiting misconfigured CI/CD workflows and stealing tokens.
-
[TECHNOLOGY] 2 sourcesnpm and PyPI supply chain attack compromises TanStack, Mistral AI and UiPath packages
A May 2026 supply‑chain attack flooded npm and PyPI with 401 malicious releases, hitting TanStack, Mistral AI and UiPath packages and prompting urgent security audits.
-
[TECHNOLOGY] 4 sourcesSoftware supply-chain attacks and AI tool vulnerabilities expose industry security gaps
TeamPCP compromised over 1,000 open‑source packages, highlighting supply‑chain risks, while a audit of Claude Code uncovered governance failures and CVEs that could steal API keys, prompting new security fixes.
-
[TECHNOLOGY] 2 sourcesMastra npm and Arch Linux AUR hit by large-scale supply-chain attacks
Attackers compromised 144 Mastra npm packages and more than 1 500 Arch AUR packages in June 2026, using stolen accounts and AI‑enhanced tools to inject credential‑stealing code, highlighting supply‑chain risks.
-
[TECHNOLOGY] 2 sourcesGitHub to disable automatic npm scripts in v12 to curb supply‑chain attacks
GitHub announced npm v12 will disable automatic install scripts and block Git and remote URL dependencies by default, requiring explicit approval to reduce supply‑chain attack risk.
-
[TECHNOLOGY] 3 sourcesMicrosoft disables 73 GitHub repositories after Miasma worm supply‑chain attack
Microsoft removed 73 GitHub repositories after the Miasma worm injected malicious commits that stole cloud credentials and leveraged AI coding tools, prompting concerns over software supply‑chain security.
-
[TECHNOLOGY] 2 sourcesGitHub Removes 73 Microsoft Repos After Miasma Malware Attack
GitHub temporarily disabled 73 Microsoft repos after a compromised account introduced the Miasma worm, causing brief CI/CD disruptions and exposing supply‑chain security risks.
-
[TECHNOLOGY] 7 sourcesSupply chain hack disables 70 Microsoft open‑source projects on GitHub
Microsoft disabled about 70 open‑source repos on GitHub after a supply‑chain attack injected password‑stealing malware, while GitHub confirmed a separate breach of roughly 3,800 internal repositories tied to a
-
[TECHNOLOGY] 2 sourcesMicrosoft warns of malicious npm packages and Miasma worm targeting developer supply chain
Microsoft flagged two malicious npm packages stealing crypto wallets and credentials, and a Miasma worm that infected 73 Microsoft GitHub repos to harvest cloud access keys, highlighting developer supply‑chain
-
[TECHNOLOGY] 2 sourcesRed Hat packages compromised by Miasma malware supply‑chain attack
Miasma malware was inserted into 32 Red Hat npm packages via a compromised employee GitHub account, stealing cloud credentials and spreading through automated republishing before being revoked.
-
[TECHNOLOGY] 5 sourcesSupply‑chain attacks on npm and Laravel packages steal cloud credentials and tokens
Coordinated supply‑chain attacks on npm Red Hat packages and Laravel‑Lang PHP tags stole cloud, browser and token credentials via CI/CD pipelines and malicious autoload code.
-
[TECHNOLOGY] 2 sourcesMicrosoft patches critical Exchange and Copilot flaws as new crypto‑wallet malware emerges
Microsoft warns of npm‑based malware stealing crypto wallets and patches critical Exchange Online and Copilot flaws that could enable data theft and remote code execution.
-
[TECHNOLOGY] 2 sourcesMicrosoft warns of crypto‑stealing malware hidden in npm packages
Microsoft flagged two malicious npm packages that deploy a RAT to steal crypto wallet data, using Hugging Face APIs for stealthy exfiltration and raising supply‑chain security concerns for developers.
-
[TECHNOLOGY] 2 sourcesGlassworm botnet taken offline after coordinated takedown
CrowdStrike, Google and The Shadowserver Foundation dismantled the Glassworm botnet on 26 May 2026, cutting its four C2 channels that targeted developers via supply‑chain attacks.
-
[TECHNOLOGY] 5 sourcesSupply chain attacks on CI/CD pipelines expose developer credentials
Supply‑chain attacks on npm packages and GitHub Actions have leaked cloud and code‑repository credentials from CI/CD pipelines, prompting calls for tighter pipeline security.
-
[TECHNOLOGY] 3 sourcesMalicious npm packages steal AI developer credentials from Claude and OpenAI tools
Two malicious npm packages targeting Claude and OpenAI Codex tools exfiltrated files and stole long‑lived developer tokens, prompting warnings about AI supply‑chain security.
-
[TECHNOLOGY] 2 sourcesTrapDoor Malware Campaign Targets Developers on npm, PyPI and Crates.io
TrapDoor malware infected 34 packages on npm, PyPI and Crates.io, targeting crypto developers and using hidden Unicode tricks to fool AI coding assistants, prompting security concerns.
-
[TECHNOLOGY] 5 sourcesGlassworm malware takedown halts developer supply‑chain attacks
CrowdStrike, Google and Shadowserver disabled the Glassworm botnet’s four C2 channels, ending a supply‑chain attack that compromised developer tools, stole credentials and crypto wallets.
-
[TECHNOLOGY] 5 sourcesTrapDoor malware campaign compromises crypto and AI developer tools
The TrapDoor supply‑chain attack spreads fake npm, PyPI and Rust packages, stealing crypto wallets, API keys and cloud credentials from developers and targeting AI coding assistants.
-
[TECHNOLOGY] 2 sourcesSupply‑chain malware campaign infects npm and PyPI packages, steals credentials from OpenAI and Mistral AI
A supply‑chain attack on npm and PyPI packages, called “Mini Shai‑Hulud,” stole cloud credentials from OpenAI, Mistral AI and many other apps; TeamPCP also compromised GitHub repos.
-
[TECHNOLOGY] 15 sourcesMini Shai-Hulud supply-chain attack compromises OpenAI devices and triggers macOS certificate rotation
Mini Shai-Hulud npm supply-chain attack hit OpenAI, forcing macOS code‑signing certificate rotation and prompting a $25k sale of stolen Mistral AI code.
Sources
all-about-security.de · android-mt.ouest-france.fr · archyworldys.com · b2b-cyber-security.de · belgiannature.be · bitcoinethereumnews.com · bleepingcomputer.com · blog.desdelinux.net · blogspan.net · borncity.com · cinemagia.wordpress.com · clubic.com · cnbaby.com · coinedition.com · coinpaper.com · conterest.de · countryrebel.com · crypto.news · cryptobriefing.com · csoonline.com.au · cyberinsider.com · cyberscoop.com · cybersecurity-news.de · cybersecuritynews.com · delphosherald.com · dev.to · devops.com · elarchivo.es · europe-infos.fr · flagthis.com · floranews.nl · gazeta-lokalna.pl · go4it.ro · Google News Business IN · hackernews.com · hackread.com · infoguerra.com.br · infoworld.com · insider.foxnews.com · inteco.es · invitehealth.substack.com · it-boltwise.de · it-connect.fr · it-daily.net · itdaily.be · ithome.com · itnerd.blog · johnstawinski.com