supply chain attack

Kaspersky links Axios npm supply chain attack to North Korea’s BlueNoroff

Kaspersky's Global Research and Analysis Team (GReAT) has identified technical links between the March 2026 Axios npm supply chain attack and BlueNoroff, a subgroup of the North Korean Lazarus hacking operation known for targeting cryptocurrency and financial technology firms, according…

153GB of stolen credentials surface from LiteLLM attack

A 153GB archive containing credentials stolen during the March 2026 LiteLLM supply chain attack has surfaced, exposing sensitive data linked to nearly 2,500 organizations including Amazon Amazon.com, Inc., Samsung, Cisco, Microsoft, NVIDIA, and Salesforce. Security firms Hudson Rock and CloudSEK…

Microsoft cuts API key lifetimes after North Korean npm attack

A North Korea-linked hacking group compromised more than 130 packages within the Mastra AI framework on npm, the JavaScript package registry owned by Microsoft through GitHub, in what multiple security firms have called one of the largest open-source supply chain…

Miasma supply chain attack toolkit surfaces as open source on GitHub

Days after the Miasma worm compromised 73 Microsoft GitHub repositories in one of the most aggressive software supply chain attacks to date, security researchers have flagged the appearance of the attack framework's source code on GitHub itself — lowering the…