Supply Chain
Poisoned dependencies and supply-chain attacks. The malicious-package stream runs to hundreds a day — shown here as the week's scale and ecosystem shape rather than a list, with the attack analysis that's worth reading below.
Malware Analysis
View all →Organizations have long known that attackers publish malicious packages to public open source registries. The more consequential question is if those packages are actually reaching enterprise development environments.
StepSecurity threat intelligence tracked 56 open source supply chain attacks from August 2025 to August 2026, roughly one every three days since March. See the data and the defenses.
Three Rust crates are compromised: arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9 each added a typosquatted build-time dependency (proc-macro1, proc-macro-en) whose build script downloads and runs a remote binary during cargo build. Full technical analysis: timeline, dropper dissection, runtime detection, IOCs, and remediation.
Three compromised Rust crates pulled in a malicious dependency that downloaded and executed cross-platform malware during Cargo builds.
Socket uncovered 77 linked Firefox extensions, including 40 that steal wallet secrets or credentials and 37 deceptive sports-score shells.
ChainDrop npm worm: 444 packages and 2,212 versions poisoned, starting with [email protected]. Payload analysis, affected package list, IOCs, and remediation steps.
Team PCP exfiltrated 78,330 secrets from 2,186 organizations via CI/CD pipelines. Analysis of the CloudSEK disclosure, why attackers target CI/CD, and how to defend.
The campaign amassed more than 75,000 installs by targeting Russian-speaking users seeking access to blocked services.