# Software supply‑chain & AI attacks on dev ecosystems

> Live situation record from CLSTR: https://clstr.news/situations/meari-baby-monitor-security-flaw-impacts-over-one-million-devices
> Updated: 2026-08-03T16:25:36.000Z. Sources: 97. Developments: 34.

Supply‑chain compromises continue to spread across JavaScript, Python, Rust and PHP ecosystems, targeting AI‑focused developers and cloud‑credential stores. The Mini Shai‑Hulud campaign, linked to TeamPCP, poisoned over 300 npm and PyPI packages—including TanStack, Mistral AI, UiPath and OpenAI’s internal tools—allowing credential theft and, in OpenAI’s case, the exfiltration of macOS code‑signing certificates. A parallel “TrapDoor” operation injected malicious utilities into npm, PyPI and Crates.io, stealing crypto‑wallet data and cloud tokens while manipulating AI coding assistants such as Claude and Cursor.

The Glassworm botnet, which had infiltrated VS Code extensions and hundreds of GitHub repositories, was dismantled by a coordinated effort from CrowdStrike, Google and the Shadowserver Foundation, cutting its four C2 channels. Shortly thereafter, the self‑replicating Miasma worm (also called Shai‑Hulud) infected dozens of Microsoft‑owned GitHub repos and Red Hat Cloud‑Services packages, prompting rapid repository takedowns and credential rotations.

New attack vectors emerged against AI agents: the “GitLost” prompt‑injection flaw lets unauthenticated users coerce GitHub’s Agentic Workflows to read private repositories, while “Agent Data Injection” attacks spoof metadata to trigger unwanted commands in Claude, Gemini and other assistants. Google disclosed an AI‑generated zero‑day that bypassed two‑factor authentication, and the GhostLock Linux‑kernel use‑after‑free bug (CVE‑2026‑43499) was patched across major distributions.

Mitigations are being rolled out: GitHub will disable automatic npm install scripts in npm v12; Microsoft warned of crypto‑stealing npm packages and released patches for Exchange and Copilot; and researchers highlighted emerging techniques such as “HalluSquatting” and “Agent Baiting” that automate repository discovery for AI agents. The combined wave of supply‑chain, AI‑assisted and credential‑theft attacks underscores the urgent need for SBOM adoption, stricter CI/CD controls, and continuous monitoring of package registries.

## Claims

- Malware on compromised Windows PCs can hijack Google Password Manager passkeys without user interaction. (corroborated by 7 sources)
- Unit 42 identified three attack techniques named Pass‑ta‑key, Silver Pass‑ta‑key and Golden Pass‑ta‑key. (corroborated by 7 sources)
- The attacks do not break the underlying cryptography of passkeys. (corroborated by 7 sources)
- Pass‑ta‑key extracts Chrome’s wrapped device identity key and uses the TPM to sign authentication requests, bypassing user verification. (corroborated by 4 sources)
- Silver Pass‑ta‑key forces a re‑enrollment window to register an attacker‑controlled verification key, allowing login without biometric checks. (corroborated by 4 sources)
- Golden Pass‑ta‑key extracts the 32‑byte Security Domain Secret, enabling decryption of all synced passkeys. (corroborated by 4 sources)
- Some services (e.g., GitHub) correctly reject forged assertions, while others (e.g., eBay) were vulnerable until patched after disclosure. (corroborated by 2 sources)
- Google has been notified and is working on remediation; no CVE identifiers have been assigned yet. (corroborated by 2 sources)

## Timeline

### 2026-08-03: Google Passkey Security Flaw Exposes Accounts to Malware

Unit 42 revealed three malware‑based techniques that let attackers hijack Google Password Manager passkeys on Windows PCs without breaking cryptography, prompting Google to work on fixes.

14 sources. https://clstr.news/cluster/google-passkey-security-flaw-allows-malware-to-hijack-accounts

### 2026-07-23: Supply‑Chain Malware Surge and Google's AI Code‑Security Preview

Malicious Shai‑Hulud copies spread on npm, prompting Google to launch CodeMender, an AI tool that scans and auto‑fixes code vulnerabilities.

2 sources. https://clstr.news/cluster/supplychain-malware-surge-and-googles-ai-codesecurity-preview

### 2026-07-22: Open‑source Software Supply Chain Hit by New Critical Libssh2 Flaw and GitHub Actions Abuse

Researchers released a public libssh2 exploit (CVE‑2026‑55200) while attackers weaponized malicious GitHub Actions to target cPanel/WHM servers (CVE‑2026‑41940), highlighting severe supply‑chain risks.

2 sources. https://clstr.news/cluster/opensource-software-supply-chain-hit-by-new-critical-libssh2-flaw-and-github-actions-abuse

### 2026-07-20: FakeGit campaign spreads SmartLoader malware via 7,600 GitHub repositories

The FakeGit campaign operates ~7,600 malicious GitHub repos, with 800 posing as AI tools, to deliver SmartLoader malware and the StealC info stealer; AI agents can be duped via 'Agent Baiting', leading to over

6 sources. https://clstr.news/cluster/fakegit-campaign-spreads-smartloader-malware-via-7600-github-repositories

### 2026-07-18: Google Threat Intelligence reports AI‑crafted zero‑day exploit and DarkSword surveillance malware

Google's Threat Intelligence unveiled the DarkSword exploit chain that records voice, screenshots and data, and disclosed the first AI‑generated zero‑day bypassing 2FA, which was patched before widespread abuse

4 sources. https://clstr.news/cluster/google-threat-intelligence-reports-aicrafted-zeroday-exploit-and-darksword-surveillance-malware

### 2026-07-17: Ghostlock Linux Kernel Vulnerability Exposes Root Access After 15‑Year Hideout

AI tool VEGA uncovered Ghostlock (CVE‑2026‑43499), a 15‑year‑old Linux kernel bug that grants root access, affecting major distributions; vendors are issuing patches as Linus Torvalds backs AI‑assisted kernel‑c

2 sources. https://clstr.news/cluster/ghostlock-linux-kernel-vulnerability-exposes-root-access-after-15year-hideout

### 2026-07-16: Emerging Cyber Attack Techniques Target Developer Tools and AI Agents

Researchers report a supply‑chain attack via malicious Vite npm packages and a new Agent Data Injection method that tricks AI assistants into executing harmful actions, exposing developers to credential theft,

7 sources. https://clstr.news/cluster/emerging-cyber-attack-techniques-target-developer-tools-and-ai-agents

### 2026-07-12: Microsoft boosts AI‑driven Windows security as cyber attacks target its services

Microsoft deploys AI to find Windows bugs, leading to larger Patch Tuesdays, as researchers report rising vishing attacks on Microsoft 365, Passkey hijacking, Visual Studio supply‑chain malware and the new Giga

10 sources. https://clstr.news/cluster/windows-malware-campaigns-compromise-visual-studio-supply-chain-and-deploy-gigawiper-backdoor

### 2026-07-08: Linux kernel 'GhostLock' vulnerability and GitHub AI prompt injection expose major security threats

A Linux kernel use‑after‑free bug (GhostLock, CVE‑2026‑43499) and a GitHub AI prompt‑injection flaw (GitLost) both enable root or private‑code exposure, raising serious security concerns.

3 sources. https://clstr.news/cluster/linux-kernel-ghostlock-vulnerability-and-github-ai-prompt-injection-expose-major-security-threats

### 2026-07-08: Supply Chain Attacks Compromise NPM Packages and Exploit AI Hallucinations

Hackers hijacked the @injectivelabs/sdk‑ts npm package to steal crypto keys, while researchers warned that AI‑generated package names are being weaponized in supply‑chain attacks.

2 sources. https://clstr.news/cluster/supply-chain-attacks-compromise-npm-packages-and-exploit-ai-hallucinations

### 2026-07-07: GitHub AI Agentic Workflows Exposed by 'GitLost' Prompt‑Injection Flaw

GitHub’s Agentic Workflows contain a “GitLost” prompt‑injection bug that lets anyone open a public issue to make the AI agent leak private repository data, bypassing safeguards with a single word.

10 sources. https://clstr.news/cluster/github-agentic-workflows-vulnerability-lets-public-issues-exfiltrate-private-repos

### 2026-07-04: Global Cyber Threats: Interpol‑Phishing Scam and TeamPCP Supply‑Chain Attack

Bitdefender exposed an INTERPOL‑impersonating phishing scam targeting SMEs globally, while the FBI warned that TeamPCP poisoned developer tools to steal cloud credentials and spread malware through supply‑chain

2 sources. https://clstr.news/cluster/global-cyber-threats-interpolphishing-scam-and-teampcp-supplychain-attack

### 2026-07-03: Supply Chain Threats Hit Mastra AI and Open‑Source Packages

TeamPCP’s multi‑vector supply‑chain attack on Mastra AI and a North Korean‑linked PolinRider campaign have poisoned npm, GitHub Actions, Arch Linux, Go modules and other open‑source repositories, compromising ​

2 sources. https://clstr.news/cluster/supply-chain-threats-hit-mastra-ai-and-opensource-packages

### 2026-06-25: GitHub Actions flaws expose 300+ repositories to supply‑chain attacks

Critical flaws in GitHub Actions let attackers hijack over 300 repositories, including Microsoft and Google projects, by exploiting misconfigured CI/CD workflows and stealing tokens.

3 sources. https://clstr.news/cluster/github-actions-vulnerabilities-threaten-hundreds-of-repositories

### 2026-06-22: npm and PyPI supply chain attack compromises TanStack, Mistral AI and UiPath packages

A May 2026 supply‑chain attack flooded npm and PyPI with 401 malicious releases, hitting TanStack, Mistral AI and UiPath packages and prompting urgent security audits.

2 sources. https://clstr.news/cluster/npm-and-pypi-supply-chain-attack-compromises-tanstack-mistral-ai-and-uipath-packages

### 2026-06-18: Software supply-chain attacks and AI tool vulnerabilities expose industry security gaps

TeamPCP compromised over 1,000 open‑source packages, highlighting supply‑chain risks, while a audit of Claude Code uncovered governance failures and CVEs that could steal API keys, prompting new security fixes.

4 sources. https://clstr.news/cluster/software-supply-chain-attacks-and-ai-tool-vulnerabilities-expose-industry-security-gaps

### 2026-06-17: Mastra npm and Arch Linux AUR hit by large-scale supply-chain attacks

Attackers compromised 144 Mastra npm packages and more than 1 500 Arch AUR packages in June 2026, using stolen accounts and AI‑enhanced tools to inject credential‑stealing code, highlighting supply‑chain risks.

2 sources. https://clstr.news/cluster/mastra-npm-and-arch-linux-aur-hit-by-large-scale-supply-chain-attacks

### 2026-06-10: GitHub to disable automatic npm scripts in v12 to curb supply‑chain attacks

GitHub announced npm v12 will disable automatic install scripts and block Git and remote URL dependencies by default, requiring explicit approval to reduce supply‑chain attack risk.

2 sources. https://clstr.news/cluster/github-to-disable-automatic-npm-scripts-in-v12-to-curb-supplychain-attacks

### 2026-06-09: Microsoft disables 73 GitHub repositories after Miasma worm supply‑chain attack

Microsoft removed 73 GitHub repositories after the Miasma worm injected malicious commits that stole cloud credentials and leveraged AI coding tools, prompting concerns over software supply‑chain security.

3 sources. https://clstr.news/cluster/microsoft-disables-73-github-repositories-after-miasma-worm-supplychain-attack

### 2026-06-09: GitHub Removes 73 Microsoft Repos After Miasma Malware Attack

GitHub temporarily disabled 73 Microsoft repos after a compromised account introduced the Miasma worm, causing brief CI/CD disruptions and exposing supply‑chain security risks.

2 sources. https://clstr.news/cluster/github-removes-73-microsoft-repos-after-miasma-malware-attack

### 2026-06-07: Supply chain hack disables 70 Microsoft open‑source projects on GitHub

Microsoft disabled about 70 open‑source repos on GitHub after a supply‑chain attack injected password‑stealing malware, while GitHub confirmed a separate breach of roughly 3,800 internal repositories tied to a

7 sources. https://clstr.news/cluster/supply-chain-hack-disables-70-microsoft-opensource-projects-on-github

### 2026-06-06: Microsoft warns of malicious npm packages and Miasma worm targeting developer supply chain

Microsoft flagged two malicious npm packages stealing crypto wallets and credentials, and a Miasma worm that infected 73 Microsoft GitHub repos to harvest cloud access keys, highlighting developer supply‑chain

2 sources. https://clstr.news/cluster/microsoft-warns-of-malicious-npm-packages-and-miasma-worm-targeting-developer-supply-chain

### 2026-06-04: Red Hat packages compromised by Miasma malware supply‑chain attack

Miasma malware was inserted into 32 Red Hat npm packages via a compromised employee GitHub account, stealing cloud credentials and spreading through automated republishing before being revoked.

2 sources. https://clstr.news/cluster/red-hat-packages-compromised-by-miasma-malware-supplychain-attack

### 2026-06-04: Supply‑chain attacks on npm and Laravel packages steal cloud credentials and tokens

Coordinated supply‑chain attacks on npm Red Hat packages and Laravel‑Lang PHP tags stole cloud, browser and token credentials via CI/CD pipelines and malicious autoload code.

5 sources. https://clstr.news/cluster/supply-chain-attacks-hit-red-hat-npm-and-laravel-php-packages

### 2026-06-03: Microsoft patches critical Exchange and Copilot flaws as new crypto‑wallet malware emerges

Microsoft warns of npm‑based malware stealing crypto wallets and patches critical Exchange Online and Copilot flaws that could enable data theft and remote code execution.

2 sources. https://clstr.news/cluster/microsoft-patches-critical-exchange-and-copilot-flaws-as-new-cryptowallet-malware-emerges

### 2026-06-03: Microsoft warns of crypto‑stealing malware hidden in npm packages

Microsoft flagged two malicious npm packages that deploy a RAT to steal crypto wallet data, using Hugging Face APIs for stealthy exfiltration and raising supply‑chain security concerns for developers.

2 sources. https://clstr.news/cluster/microsoft-warns-of-cryptostealing-malware-hidden-in-npm-packages

### 2026-06-01: Glassworm botnet taken offline after coordinated takedown

CrowdStrike, Google and The Shadowserver Foundation dismantled the Glassworm botnet on 26 May 2026, cutting its four C2 channels that targeted developers via supply‑chain attacks.

2 sources. https://clstr.news/cluster/glassworm-botnet-taken-offline-after-coordinated-takedown

### 2026-05-31: Supply chain attacks on CI/CD pipelines expose developer credentials

Supply‑chain attacks on npm packages and GitHub Actions have leaked cloud and code‑repository credentials from CI/CD pipelines, prompting calls for tighter pipeline security.

5 sources. https://clstr.news/cluster/supply-chain-attacks-on-cicd-pipelines-expose-developer-credentials

### 2026-05-31: Malicious npm packages steal AI developer credentials from Claude and OpenAI tools

Two malicious npm packages targeting Claude and OpenAI Codex tools exfiltrated files and stole long‑lived developer tokens, prompting warnings about AI supply‑chain security.

3 sources. https://clstr.news/cluster/malicious-npm-packages-steal-ai-developer-credentials-from-claude-and-openai-tools

### 2026-05-28: TrapDoor Malware Campaign Targets Developers on npm, PyPI and Crates.io

TrapDoor malware infected 34 packages on npm, PyPI and Crates.io, targeting crypto developers and using hidden Unicode tricks to fool AI coding assistants, prompting security concerns.

2 sources. https://clstr.news/cluster/trapdoor-malware-campaign-targets-developers-on-npm-pypi-and-cratesio

### 2026-05-27: Glassworm malware takedown halts developer supply‑chain attacks

CrowdStrike, Google and Shadowserver disabled the Glassworm botnet’s four C2 channels, ending a supply‑chain attack that compromised developer tools, stole credentials and crypto wallets.

5 sources. https://clstr.news/cluster/glassworm-malware-takedown-halts-developer-supplychain-attacks

### 2026-05-25: TrapDoor malware campaign compromises crypto and AI developer tools

The TrapDoor supply‑chain attack spreads fake npm, PyPI and Rust packages, stealing crypto wallets, API keys and cloud credentials from developers and targeting AI coding assistants.

5 sources. https://clstr.news/cluster/trapdoor-malware-campaign-compromises-crypto-and-ai-developer-tools

### 2026-05-22: Supply‑chain malware campaign infects npm and PyPI packages, steals credentials from OpenAI and Mistral AI

A supply‑chain attack on npm and PyPI packages, called “Mini Shai‑Hulud,” stole cloud credentials from OpenAI, Mistral AI and many other apps; TeamPCP also compromised GitHub repos.

2 sources. https://clstr.news/cluster/supplychain-malware-campaign-infects-npm-and-pypi-packages-steals-credentials-from-openai-and-mistra

### 2026-05-14: Mini Shai-Hulud supply-chain attack compromises OpenAI devices and triggers macOS certificate rotation

Mini Shai-Hulud npm supply-chain attack hit OpenAI, forcing macOS code‑signing certificate rotation and prompting a $25k sale of stolen Mistral AI code.

15 sources. https://clstr.news/cluster/npm-supply-chain-attacks-steal-developer-credentials-via-tor-and-maintainer-hijack

---
Cite as: Software supply‑chain & AI attacks on dev ecosystems. CLSTR, https://clstr.news/situations/meari-baby-monitor-security-flaw-impacts-over-one-million-devices
