<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Vigilance | Supply Chain Attack Library</title>
    <link>https://vigihq.com/attacks</link>
    <atom:link href="https://vigihq.com/attacks/rss.xml" rel="self" type="application/rss+xml" />
    <description>Real software supply chain attacks, one page each, with affected versions, sources and how to check.</description>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 00:00:00 GMT</lastBuildDate>
    <item>
      <title>@apexacc/cli Supply Chain Attack (1.5.122): What Happened and How to Check</title>
      <link>https://vigihq.com/attacks/apexacc-cli-defender-blinding-c2-loader</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/apexacc-cli-defender-blinding-c2-loader</guid>
      <pubDate>Thu, 17 Sep 2026 00:00:00 GMT</pubDate>
      <category>npm</category>
      <description>@apexacc/cli 1.5.122 on npm turns off Windows Defender and Smart App Control, then runs commands from a server. How to check and clean up.</description>
    </item>
    <item>
      <title>arrayref, internment, append-only-vec Supply Chain Attack (0.3.10, 0.8.7, 0.1.9)</title>
      <link>https://vigihq.com/attacks/arrayref-internment-append-only-vec-crates-io-compro</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/arrayref-internment-append-only-vec-crates-io-compro</guid>
      <pubDate>Thu, 20 Aug 2026 00:00:00 GMT</pubDate>
      <category>crates.io</category>
      <description>On 20 Aug 2026 attackers published arrayref 0.3.10, internment 0.8.7 and append-only-vec 0.1.9 on crates.io with a malicious dependency.</description>
    </item>
    <item>
      <title>keyv and cacheable npm Worm (keyv 6.0.0): What Happened and How to Check</title>
      <link>https://vigihq.com/attacks/keyv-cacheable-npm-worm-shai-hulud-third-wave</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/keyv-cacheable-npm-worm-shai-hulud-third-wave</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate>
      <category>npm</category>
      <description>On 4 Aug 2026 a worm hit keyv 6.0.0, cacheable 2.5.1 and related npm packages. See the bad versions, indicators, a check command and the fix.</description>
    </item>
    <item>
      <title>SleeperGem RubyGems Attack (git_credential_manager 2.8.0-2.8.3)</title>
      <link>https://vigihq.com/attacks/sleepergem-dormant-maintainer-rubygems-hijacks</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/sleepergem-dormant-maintainer-rubygems-hijacks</guid>
      <pubDate>Sat, 18 Jul 2026 00:00:00 GMT</pubDate>
      <category>RubyGems</category>
      <description>SleeperGem hit RubyGems in July 2026: git_credential_manager 2.8.0-2.8.3, Dendreo 1.1.3-1.1.4 and a fastlane plugin 0.3.2. IOCs and checks.</description>
    </item>
    <item>
      <title>Mastra npm Supply Chain Attack (mastra 1.13.1): What Happened</title>
      <link>https://vigihq.com/attacks/mastra-ai-npm-compromise-sapphire-sleet</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/mastra-ai-npm-compromise-sapphire-sleet</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <category>npm</category>
      <description>140+ @mastra npm packages, including mastra 1.13.1 and @mastra/core 1.42.1, gained the malicious easy-day-js dependency. Indicators and fixes.</description>
    </item>
    <item>
      <title>onering Rust Crate Supply Chain Attack (1.4.1): What Happened and How to Check</title>
      <link>https://vigihq.com/attacks/onering-crate-build-script-code-exfiltration</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/onering-crate-build-script-code-exfiltration</guid>
      <pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate>
      <category>crates.io</category>
      <description>onering 1.4.1 on crates.io ran a build script that sent your latest git commit diff to a Sentry endpoint. Here is how to check and respond.</description>
    </item>
    <item>
      <title>durabletask PyPI Supply Chain Attack (1.4.1 to 1.4.3): What Happened</title>
      <link>https://vigihq.com/attacks/microsoft-durabletask-pypi-compromise-teampcp</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/microsoft-durabletask-pypi-compromise-teampcp</guid>
      <pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate>
      <category>PyPI</category>
      <description>Microsoft durabletask 1.4.1, 1.4.2 and 1.4.3 on PyPI carried a credential-stealing worm on 19 May 2026. See indicators, a check command and the fix.</description>
    </item>
    <item>
      <title>Nx Console Supply Chain Attack (18.95.0): What Happened and How to Check</title>
      <link>https://vigihq.com/attacks/nx-console-vs-code-extension-18-95-0-compromise-team</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/nx-console-vs-code-extension-18-95-0-compromise-team</guid>
      <pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate>
      <category>IDE extension</category>
      <description>Nx Console VS Code extension 18.95.0 carried a credential stealer on 18 May 2026. Patched in 18.100.0. Indicators, checks and steps.</description>
    </item>
    <item>
      <title>TanStack npm Supply Chain Attack (1.169.8): What Happened and How to Check</title>
      <link>https://vigihq.com/attacks/tanstack-npm-compromise-mini-shai-hulud</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/tanstack-npm-compromise-mini-shai-hulud</guid>
      <pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate>
      <category>npm</category>
      <description>84 malicious versions of 42 @tanstack packages, including router 1.169.5 and 1.169.8, stole CI secrets on 11 May 2026. Learn how to check.</description>
    </item>
    <item>
      <title>JDownloader Installer Supply Chain Attack (May 2026): What Happened and How to Check</title>
      <link>https://vigihq.com/attacks/jdownloader-official-site-installer-swap</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/jdownloader-official-site-installer-swap</guid>
      <pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate>
      <category>vendor binary</category>
      <description>On 6-7 May 2026 the official JDownloader site served trojanized Windows and Linux installers. See who was affected, the indicators, and how to check.</description>
    </item>
    <item>
      <title>CPUID CPU-Z 2.19 and HWMonitor 1.63 Download Compromise: What Happened</title>
      <link>https://vigihq.com/attacks/cpuid-cpu-z-hwmonitor-download-compromise</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/cpuid-cpu-z-hwmonitor-download-compromise</guid>
      <pubDate>Thu, 09 Apr 2026 00:00:00 GMT</pubDate>
      <category>vendor binary</category>
      <description>CPU-Z 2.19 and HWMonitor 1.63 downloads from cpuid.com carried STX RAT on 9-10 April 2026. See the indicators, how to check and what to do.</description>
    </item>
    <item>
      <title>DAEMON Tools Supply Chain Attack (12.5.0.2421-12.5.0.2434)</title>
      <link>https://vigihq.com/attacks/daemon-tools-trojanized-installers</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/daemon-tools-trojanized-installers</guid>
      <pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate>
      <category>vendor binary</category>
      <description>Official signed DAEMON Tools Lite installers 12.5.0.2421 to 12.5.0.2434 carried a backdoor from 8 April 2026. Fixed in 12.6.0.2445. IOCs and checks.</description>
    </item>
    <item>
      <title>Axios npm Supply Chain Attack (1.14.1): What Happened and How to Check</title>
      <link>https://vigihq.com/attacks/axios-npm-2026</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/axios-npm-2026</guid>
      <pubDate>Tue, 31 Mar 2026 00:00:00 GMT</pubDate>
      <category>npm</category>
      <description>Axios 1.14.1 and 0.30.4 on npm pulled in plain-crypto-js 4.2.1, which installs a remote access trojan. Versions, indicators and a check command.</description>
    </item>
    <item>
      <title>LiteLLM Supply Chain Attack: Versions 1.82.7 and 1.82.8 on PyPI</title>
      <link>https://vigihq.com/attacks/litellm-pypi-2026</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/litellm-pypi-2026</guid>
      <pubDate>Tue, 24 Mar 2026 00:00:00 GMT</pubDate>
      <category>PyPI</category>
      <description>LiteLLM 1.82.7 and 1.82.8 on PyPI stole cloud keys and SSH keys. See the indicators, how to check with pip, and why uninstalling is not enough.</description>
    </item>
    <item>
      <title>Trivy Supply Chain Attack: The v0.69.4 and setup-trivy Compromise Explained</title>
      <link>https://vigihq.com/attacks/trivy-2026</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/trivy-2026</guid>
      <pubDate>Thu, 19 Mar 2026 00:00:00 GMT</pubDate>
      <category>CI action</category>
      <description>Trivy v0.69.4, trivy-action and setup-trivy were poisoned on 19 March 2026 (CVE-2026-33634). Timeline, indicators, safe versions and how to check CI.</description>
    </item>
    <item>
      <title>Offside Wallet Theft Factory (Firefox Add-ons): What Happened and How to Check</title>
      <link>https://vigihq.com/attacks/offside-wallet-theft-factory-firefox-add-ons-convert</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/offside-wallet-theft-factory-firefox-add-ons-convert</guid>
      <pubDate>Mon, 09 Mar 2026 00:00:00 GMT</pubDate>
      <category>browser extension</category>
      <description>Nine Firefox add-ons shipped as sports-score tools, then updated into fake Rabby wallet stealers. See the IDs, versions and how to check.</description>
    </item>
    <item>
      <title>QuickLens Chrome Extension Supply Chain Attack (Feb 2026): What Happened and How to Check</title>
      <link>https://vigihq.com/attacks/quicklens-shotbird-ownership-transfer-hijack</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/quicklens-shotbird-ownership-transfer-hijack</guid>
      <pubDate>Tue, 17 Feb 2026 00:00:00 GMT</pubDate>
      <category>browser extension</category>
      <description>QuickLens (about 7,000 users) turned malicious on 17 Feb 2026 after a sale. ShotBird followed. See the extension IDs, behavior and how to check.</description>
    </item>
    <item>
      <title>eScan Antivirus Update Server Compromise (reload.exe): What Happened</title>
      <link>https://vigihq.com/attacks/escan-antivirus-update-server-compromise-2026</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/escan-antivirus-update-server-compromise-2026</guid>
      <pubDate>Tue, 20 Jan 2026 00:00:00 GMT</pubDate>
      <category>vendor binary</category>
      <description>On 20 Jan 2026 a hacked eScan regional update server pushed a trojanized reload.exe to customers. See the indicators, a check command and the fix.</description>
    </item>
    <item>
      <title>Trust Wallet Extension Supply Chain Attack (2.68)</title>
      <link>https://vigihq.com/attacks/trust-wallet-browser-extension-v2-68-compromise</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/trust-wallet-browser-extension-v2-68-compromise</guid>
      <pubDate>Wed, 24 Dec 2025 00:00:00 GMT</pubDate>
      <category>browser extension</category>
      <description>Trust Wallet browser extension 2.68 stole seed phrases after a leaked Chrome Web Store API key. Fixed in 2.69. Indicators, checks and steps.</description>
    </item>
    <item>
      <title>Shai-Hulud 2.0 npm Worm Supply Chain Attack (Nov 2025): What Happened and How to Check</title>
      <link>https://vigihq.com/attacks/shai-hulud-2-0-second-wave</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/shai-hulud-2-0-second-wave</guid>
      <pubDate>Mon, 24 Nov 2025 00:00:00 GMT</pubDate>
      <category>npm</category>
      <description>Shai-Hulud 2.0 backdoored 796 npm packages on 24 Nov 2025 with a preinstall script. Learn the indicators, how to check your tree and what to rotate.</description>
    </item>
    <item>
      <title>org.mvnpm:posthog-node Supply Chain Attack (4.18.1): What Happened</title>
      <link>https://vigihq.com/attacks/shai-hulud-v2-reaches-maven-central-via-mvnpm-mirror</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/shai-hulud-v2-reaches-maven-central-via-mvnpm-mirror</guid>
      <pubDate>Mon, 24 Nov 2025 00:00:00 GMT</pubDate>
      <category>Maven</category>
      <description>Shai-Hulud v2 reached Maven Central in org.mvnpm:posthog-node 4.18.1, a mirrored npm build. See the indicators, how to check and what to do.</description>
    </item>
    <item>
      <title>GlassWorm VS Code Extension Worm (codejoy 1.8.3): What Happened and How to Check</title>
      <link>https://vigihq.com/attacks/glassworm-self-propagating-worm-on-open-vsx-vs-code-</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/glassworm-self-propagating-worm-on-open-vsx-vs-code-</guid>
      <pubDate>Fri, 17 Oct 2025 00:00:00 GMT</pubDate>
      <category>IDE extension</category>
      <description>GlassWorm hid code in invisible Unicode inside Open VSX extensions such as codejoy.codejoy-vscode-extension 1.8.3 and 1.8.4. Indicators and checks.</description>
    </item>
    <item>
      <title>chalk and debug npm Supply Chain Attack (chalk 5.6.1, debug 4.4.2)</title>
      <link>https://vigihq.com/attacks/chalk-debug-ansi-styles-maintainer-phishing-compromi</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/chalk-debug-ansi-styles-maintainer-phishing-compromi</guid>
      <pubDate>Mon, 08 Sep 2025 00:00:00 GMT</pubDate>
      <category>npm</category>
      <description>On 8 Sept 2025 phishing let attackers publish 18 npm packages, including chalk 5.6.1 and debug 4.4.2, with crypto-theft code. Versions and checks.</description>
    </item>
    <item>
      <title>Nx npm Supply Chain Attack (s1ngularity): What Happened and How to Check</title>
      <link>https://vigihq.com/attacks/nx-s1ngularity-compromise</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/nx-s1ngularity-compromise</guid>
      <pubDate>Tue, 26 Aug 2025 00:00:00 GMT</pubDate>
      <category>npm</category>
      <description>Eight malicious nx releases, including 21.5.0 and 20.9.0, stole secrets with telemetry.js and local AI CLIs. See versions, indicators and fixes.</description>
    </item>
    <item>
      <title>QuickFox VPN Supply Chain Attack (3.0.51.0 to 3.59.5): What Happened and How to Check</title>
      <link>https://vigihq.com/attacks/quickfox-vpn-trojanized-windows-installer</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/quickfox-vpn-trojanized-windows-installer</guid>
      <pubDate>Fri, 01 Aug 2025 00:00:00 GMT</pubDate>
      <category>vendor binary</category>
      <description>The QuickFox Windows installer, 3.0.51.0 through 3.59.5, carried injected JavaScript that loaded the FDMTP backdoor. Fixed in 3.59.6.</description>
    </item>
    <item>
      <title>num2words PyPI Supply Chain Attack (0.5.15): What Happened and How to Check</title>
      <link>https://vigihq.com/attacks/num2words-hijack-pypi-phishing-campaign-scavenger-ma</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/num2words-hijack-pypi-phishing-campaign-scavenger-ma</guid>
      <pubDate>Mon, 28 Jul 2025 00:00:00 GMT</pubDate>
      <category>PyPI</category>
      <description>PyPI package num2words 0.5.15 and 0.5.16 carried the Scavenger loader after a phishing attack on the maintainer. Indicators and checks.</description>
    </item>
    <item>
      <title>eslint-config-prettier npm Supply Chain Attack (10.1.6, 10.1.7)</title>
      <link>https://vigihq.com/attacks/eslint-config-prettier-eslint-plugin-prettier-phishi</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/eslint-config-prettier-eslint-plugin-prettier-phishi</guid>
      <pubDate>Fri, 18 Jul 2025 00:00:00 GMT</pubDate>
      <category>npm</category>
      <description>On 18 July 2025 phishing led to bad eslint-config-prettier 8.10.1, 9.1.1, 10.1.6 and 10.1.7 that run a Windows DLL on install. CVE-2025-54313.</description>
    </item>
    <item>
      <title>Amazon Q Developer for VS Code Supply Chain Attack (1.84.0): What Happened</title>
      <link>https://vigihq.com/attacks/amazon-q-developer-for-vs-code-malicious-commit</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/amazon-q-developer-for-vs-code-malicious-commit</guid>
      <pubDate>Thu, 17 Jul 2025 00:00:00 GMT</pubDate>
      <category>IDE extension</category>
      <description>Amazon Q Developer for VS Code 1.84.0 shipped a malicious commit with data-wiping prompts. Fixed in 1.85.0. See how to check and what to do.</description>
    </item>
    <item>
      <title>Gravity Forms Supply Chain Attack (2.9.11.1, 2.9.12): What Happened and How to Check</title>
      <link>https://vigihq.com/attacks/gravity-forms-wordpress-plugin-compromise</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/gravity-forms-wordpress-plugin-compromise</guid>
      <pubDate>Wed, 09 Jul 2025 00:00:00 GMT</pubDate>
      <category>other</category>
      <description>Gravity Forms 2.9.11.1 and 2.9.12, downloaded manually or by Composer on 9-11 July 2025, held a backdoor. Update to 2.9.13 and check for the indicators.</description>
    </item>
    <item>
      <title>RedDirection Browser Extension Attack (Color Picker Geco): What Happened</title>
      <link>https://vigihq.com/attacks/reddirection-campaign-color-picker-geco-and-17-other</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/reddirection-campaign-color-picker-geco-and-17-other</guid>
      <pubDate>Fri, 27 Jun 2025 00:00:00 GMT</pubDate>
      <category>browser extension</category>
      <description>RedDirection: 18 Chrome and Edge extensions, including Color Picker Geco, turned malicious after updates and reported browsing to attacker servers.</description>
    </item>
    <item>
      <title>ETHcode VS Code Extension Supply Chain Attack (0.5.0)</title>
      <link>https://vigihq.com/attacks/ethcode-vs-code-extension-malicious-pull-request</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/ethcode-vs-code-extension-malicious-pull-request</guid>
      <pubDate>Tue, 17 Jun 2025 00:00:00 GMT</pubDate>
      <category>IDE extension</category>
      <description>ETHcode 0.5.0 for VS Code shipped a fake dependency, keythereum-utils, that runs a hidden PowerShell script. Fixed in 0.5.1. Checks and steps.</description>
    </item>
    <item>
      <title>gluestack and react-native-aria Supply Chain Attack: What Happened and How to Check</title>
      <link>https://vigihq.com/attacks/gluestack-react-native-aria-compromise</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/gluestack-react-native-aria-compromise</guid>
      <pubDate>Fri, 06 Jun 2025 00:00:00 GMT</pubDate>
      <category>npm</category>
      <description>17 @react-native-aria and @gluestack-ui npm packages shipped a remote access trojan in June 2025. See versions, indicators and how to check.</description>
    </item>
    <item>
      <title>Notepad++ Update Supply Chain Attack (8.8.2 to 8.8.9): What Happened and How to Check</title>
      <link>https://vigihq.com/attacks/notepad-update-infrastructure-compromise</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/notepad-update-infrastructure-compromise</guid>
      <pubDate>Sun, 01 Jun 2025 00:00:00 GMT</pubDate>
      <category>vendor binary</category>
      <description>Attackers hijacked Notepad++ WinGUp update traffic in 2025 and delivered trojanized updates (8.8.2 to 8.8.9). Fixed in 8.9.1. See indicators and checks.</description>
    </item>
    <item>
      <title>RVTools Installer Attack (Bumblebee, May 2025): What Happened and How to Check</title>
      <link>https://vigihq.com/attacks/rvtools-installer-compromise-bumblebee</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/rvtools-installer-compromise-bumblebee</guid>
      <pubDate>Mon, 12 May 2025 00:00:00 GMT</pubDate>
      <category>vendor binary</category>
      <description>A trojanized RVTools installer delivered the Bumblebee loader through version.dll in May 2025. Hash check, indicators and what to do.</description>
    </item>
    <item>
      <title>rand-user-agent npm Supply Chain Attack (2.0.83, 2.0.84, 1.0.110)</title>
      <link>https://vigihq.com/attacks/rand-user-agent-rat-compromise</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/rand-user-agent-rat-compromise</guid>
      <pubDate>Mon, 05 May 2025 00:00:00 GMT</pubDate>
      <category>npm</category>
      <description>rand-user-agent 2.0.83, 2.0.84 and 1.0.110 on npm carried a remote access trojan in May 2025. Clean: 2.0.82. IOCs, checks and steps.</description>
    </item>
    <item>
      <title>xrpl.js Supply Chain Attack (4.2.1 to 4.2.4, 2.14.2): What Happened and How to Check</title>
      <link>https://vigihq.com/attacks/xrpl-js-xrp-ledger-sdk-backdoor</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/xrpl-js-xrp-ledger-sdk-backdoor</guid>
      <pubDate>Mon, 21 Apr 2025 00:00:00 GMT</pubDate>
      <category>npm</category>
      <description>xrpl npm versions 4.2.1 to 4.2.4 and 2.14.2 stole wallet keys. Fixed in 4.2.5 and 2.14.3. See indicators, how to check and what to do.</description>
    </item>
    <item>
      <title>tj-actions/changed-files Supply Chain Attack (v45.0.7 and Earlier): What Happened and How to Check</title>
      <link>https://vigihq.com/attacks/tj-actions-changed-files-github-action-compromise</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/tj-actions-changed-files-github-action-compromise</guid>
      <pubDate>Fri, 14 Mar 2025 00:00:00 GMT</pubDate>
      <category>CI action</category>
      <description>On 14 Mar 2025 attackers repointed tj-actions/changed-files tags to a commit that leaked CI secrets (CVE-2025-30066). Fixed in v46.0.1.</description>
    </item>
    <item>
      <title>reviewdog/action-setup Supply Chain Attack (v1): What Happened and How to Check</title>
      <link>https://vigihq.com/attacks/reviewdog-action-setup-compromise</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/reviewdog-action-setup-compromise</guid>
      <pubDate>Tue, 11 Mar 2025 00:00:00 GMT</pubDate>
      <category>CI action</category>
      <description>reviewdog/action-setup@v1 leaked CI secrets into workflow logs on 11 March 2025 (CVE-2025-30154). Affected actions, log check, and fixes.</description>
    </item>
    <item>
      <title>Cyberhaven Chrome Extension Supply Chain Attack (24.10.4)</title>
      <link>https://vigihq.com/attacks/cyberhaven-chrome-extension-compromise</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/cyberhaven-chrome-extension-compromise</guid>
      <pubDate>Wed, 25 Dec 2024 00:00:00 GMT</pubDate>
      <category>browser extension</category>
      <description>Cyberhaven Chrome extension 24.10.4 stole cookies and sessions after a phishing attack on 24 Dec 2024. Fixed in 24.10.5. IOCs, checks and steps.</description>
    </item>
    <item>
      <title>Rspack and Vant Supply Chain Attack (1.1.7): What Happened and How to Check</title>
      <link>https://vigihq.com/attacks/rspack-vant-npm-token-compromise</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/rspack-vant-npm-token-compromise</guid>
      <pubDate>Thu, 19 Dec 2024 00:00:00 GMT</pubDate>
      <category>npm</category>
      <description>@rspack/core and @rspack/cli 1.1.7 and several vant versions shipped an XMRig miner via stolen npm tokens. Fixed in 1.1.8. See how to check.</description>
    </item>
    <item>
      <title>Chrome Extension Supply Chain Attack (Dec 2024): Reader Mode, Cyberhaven and Others</title>
      <link>https://vigihq.com/attacks/december-2024-chrome-web-store-oauth-phishing-wave-b</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/december-2024-chrome-web-store-oauth-phishing-wave-b</guid>
      <pubDate>Wed, 18 Dec 2024 00:00:00 GMT</pubDate>
      <category>browser extension</category>
      <description>Phishing for Chrome Web Store developer access let attackers push malicious updates to 35+ extensions in Dec 2024. See the IDs, domains and checks.</description>
    </item>
    <item>
      <title>Ultralytics PyPI Supply Chain Attack (8.3.41): What Happened and How to Check</title>
      <link>https://vigihq.com/attacks/ultralytics-pypi-compromise-github-actions-cache-poi</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/ultralytics-pypi-compromise-github-actions-cache-poi</guid>
      <pubDate>Wed, 04 Dec 2024 00:00:00 GMT</pubDate>
      <category>PyPI</category>
      <description>ultralytics 8.3.41, 8.3.42, 8.3.45 and 8.3.46 on PyPI installed an XMRig cryptominer. Indicators, how to check, and what to do.</description>
    </item>
    <item>
      <title>aiocpa PyPI Supply Chain Attack (0.1.13, 0.1.14): What Happened and How to Check</title>
      <link>https://vigihq.com/attacks/aiocpa-crypto-pay-library-poisoned-release</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/aiocpa-crypto-pay-library-poisoned-release</guid>
      <pubDate>Wed, 20 Nov 2024 00:00:00 GMT</pubDate>
      <category>PyPI</category>
      <description>aiocpa 0.1.13 and 0.1.14 on PyPI sent Crypto Pay API tokens to a Telegram bot. See affected versions, indicators, and how to check.</description>
    </item>
    <item>
      <title>aiocpa PyPI Supply Chain Attack (0.1.13, 0.1.14): What Happened and How to Check</title>
      <link>https://vigihq.com/attacks/aiocpa-pypi-infostealer-implant</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/aiocpa-pypi-infostealer-implant</guid>
      <pubDate>Wed, 20 Nov 2024 00:00:00 GMT</pubDate>
      <category>PyPI</category>
      <description>aiocpa 0.1.13 and 0.1.14 on PyPI hid an infostealer that sent Crypto Pay credentials to a Telegram bot. See indicators and how to check.</description>
    </item>
    <item>
      <title>@lottiefiles/lottie-player Supply Chain Attack (2.0.5 to 2.0.7): What Happened and How to Check</title>
      <link>https://vigihq.com/attacks/lottiefiles-lottie-player-compromise</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/lottiefiles-lottie-player-compromise</guid>
      <pubDate>Wed, 30 Oct 2024 00:00:00 GMT</pubDate>
      <category>npm</category>
      <description>On 30 Oct 2024 attackers published @lottiefiles/lottie-player 2.0.5, 2.0.6 and 2.0.7 with a crypto wallet drainer. Clean: 2.0.4 and 2.0.8.</description>
    </item>
    <item>
      <title>Procolored Printer Software Malware (XRed, SnipVex): What Happened</title>
      <link>https://vigihq.com/attacks/procolored-printer-software-malware-distribution</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/procolored-printer-software-malware-distribution</guid>
      <pubDate>Tue, 01 Oct 2024 00:00:00 GMT</pubDate>
      <category>vendor binary</category>
      <description>Procolored printer software for the F8, F13, F13 Pro, V6, V11 Pro and VF13 Pro carried XRed and SnipVex malware until May 2025. Checks and steps.</description>
    </item>
    <item>
      <title>Chrome Extension Hijack Wave (16 Extensions, 3.2M Users): What Happened and How to Check</title>
      <link>https://vigihq.com/attacks/gitlab-reported-chrome-extension-hijack-wave-16-exte</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/gitlab-reported-chrome-extension-hijack-wave-16-exte</guid>
      <pubDate>Thu, 04 Jul 2024 00:00:00 GMT</pubDate>
      <category>browser extension</category>
      <description>Sixteen Chrome extensions, including Blipshot and KProxy, got malicious updates in 2024. See the extension IDs, domains, and how to check.</description>
    </item>
    <item>
      <title>pingdomv3 PyPI Revival Hijack (1.0.1): What Happened and How to Check</title>
      <link>https://vigihq.com/attacks/pingdomv3-revival-hijack</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/pingdomv3-revival-hijack</guid>
      <pubDate>Fri, 12 Apr 2024 00:00:00 GMT</pubDate>
      <category>PyPI</category>
      <description>The pingdomv3 PyPI name was deleted and re-registered by a new owner who added code that fetches and runs remote Python in Jenkins builds.</description>
    </item>
    <item>
      <title>JAVS Viewer Supply Chain Attack (8.3.7.250-1): What Happened and How to Check</title>
      <link>https://vigihq.com/attacks/javs-viewer-courtroom-recorder-backdoor</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/javs-viewer-courtroom-recorder-backdoor</guid>
      <pubDate>Tue, 05 Mar 2024 00:00:00 GMT</pubDate>
      <category>vendor binary</category>
      <description>The JAVS Viewer 8.3.7.250-1 installer from the official site held a backdoor (CVE-2024-4978). Fixed in 8.3.8. See the indicators and how to check.</description>
    </item>
    <item>
      <title>XZ Utils Backdoor (CVE-2024-3094, 5.6.0 and 5.6.1): What Happened</title>
      <link>https://vigihq.com/attacks/xz-utils-backdoor</link>
      <guid isPermaLink="true">https://vigihq.com/attacks/xz-utils-backdoor</guid>
      <pubDate>Sat, 24 Feb 2024 00:00:00 GMT</pubDate>
      <category>source tarball</category>
      <description>XZ Utils 5.6.0 and 5.6.1 contained a backdoor, CVE-2024-3094, that targeted sshd. Affected versions, how to check, and what to do.</description>
    </item>
  </channel>
</rss>
