Skip to content
Threat Digest
Explainers Data Breaches Vulnerabilities & CVEs Ransomware & Malware
Nation-State Threats Security Tools Compliance & Policy Cloud Security Threat Intelligence

#supply-chain-attack

Hacked Smart Slider plugin update injecting backdoors into WordPress dashboard
Vulnerabilities & CVEs

Smart Slider's Poisoned Update: Hackers Slip Backdoors into 900K WordPress Sites

Imagine trusting an update to safeguard your site—only for it to unleash a horde of backdoors. That's the nightmare hackers delivered via Smart Slider 3 Pro, hitting nearly a million WordPress installs.

5 min read 1 month, 1 week ago
List of 36 malicious strapi-plugin npm packages targeting Redis and PostgreSQL databases
Ransomware & Malware

36 Fake npm Strapi Plugins Slip Redis and Postgres Backdoors into Dev Pipelines

Imagine firing up npm install for a quick Strapi tweak, only to hand attackers your database keys and a persistent foothold. That's the nightmare 36 malicious packages just unleashed on unsuspecting devs.

5 min read 1 month, 2 weeks ago
Digital assembly line depicting hackers scaling social engineering attacks on NPM maintainers like the Axios incident
Vulnerabilities & CVEs

Axios NPM Hijack: When Social Engineering Goes Factory-Scale

We all figured Axios was untouchable, that rock-solid HTTP client millions rely on. But hackers didn't crack code—they conned humans, at industrial scale.

5 min read 1 month, 2 weeks ago
North Korean hackers compromising Axios NPM package supply chain attack visualization
Vulnerabilities & CVEs

North Korean Hackers Turn Axios NPM into Malware Machine: Supply Chain's New Frontline

North Korean hackers didn't just breach an npm account—they hijacked Axios, a package pulled 100 million times weekly, and laced it with self-deleting malware. This week's threats expose how attackers are betting big on the software build process.

5 min read 1 month, 2 weeks ago
Digital illustration of a shadowy figure cloning a CEO's Slack workspace to breach Axios npm package
Nation-State Threats

North Korean Hackers' Slick Slack Trick: Inside the Axios npm Compromise

What if the next update to your favorite npm package came laced with North Korean spyware? That's exactly what happened to Axios — and it started with a too-perfect Slack invite.

4 min read 1 month, 2 weeks ago
TeamPCP supply chain campaign timeline with Databricks, ransomware tracks, and AstraZeneca icons
Cloud Security

TeamPCP's Supply Chain Onslaught Hits Databricks, Splits Ransomware Into Two Deadly Tracks

Databricks is scrambling to verify a potential TeamPCP breach, while the group unleashes dual ransomware tracks and dumps AstraZeneca data for free. This isn't just another hack—it's a monetization masterclass.

5 min read 1 month, 2 weeks ago
Visualization of TeamPCP supply chain attack flow from LiteLLM to cloud breaches
Compliance & Policy

Mercor Breach Exposes TeamPCP's LiteLLM Rampage in Real Time

Mercor just admitted it: TeamPCP's LiteLLM poison pill hit hard. Wiz peels back the post-breach playbook, showing how attackers feast on cloud creds.

5 min read 1 month, 2 weeks ago
Malicious Axios npm package details with RAT indicators on screen
Compliance & Policy

Axios npm Poisoning: Hackers Hijack Your Dev Secrets via 100M Downloads

One npm install, and boom—your cloud keys are en route to a hacker's server. Axios, the unsung hero of JS networking, just got turned into a trojan horse.

4 min read 1 month, 2 weeks ago
Diagram of TeamPCP supply chain attack infiltrating CI/CD pipelines via PyPI and GitHub
Nation-State Threats

TeamPCP's Ruthless Hijack of Security Scanners: 500K Machines, 300GB Stolen

Attackers slipped infostealers into GitHub Actions and PyPI, turning vulnerability scanners against their users. Over 500,000 machines lost cloud tokens, SSH keys, and Kubernetes secrets in this escalating nightmare.

5 min read 1 month, 2 weeks ago
← Newer Page 4 of 4

Categories

Explainers Data Breaches Vulnerabilities & CVEs Ransomware & Malware Nation-State Threats Security Tools Compliance & Policy Cloud Security
Threat Digest

Threat intelligence. Zero noise.

More

  • RSS Feed
  • Sitemap
  • About
  • Editorial Process
  • Advertise

Legal

  • Privacy
  • Terms
  • Work With Us

Our Network

The AI Catchup AI & Machine Learning Threat Digest Cybersecurity Legal AI Beat Legal Tech Fintech Rundown Finance & Banking DevTools Feed Developer Tools Open Source Beat Open Source Fintech Dose Crypto & DeFi Chip Beat Semiconductors AdTech Beat Ad Technology Supply Chain Beat Logistics

© 2026 Threat Digest. All rights reserved.

🏠Home 🔍Search 🔖Saved 📂Categories
Privacy & cookies

We use a privacy-respecting analytics tool to count page views — no personal profiles, no ad tracking, no third-party cookies. Accept to help us understand which stories matter to readers.

Details