Search
For "supply chain" across CVEs, vendor advisories, threat actors, IOCs, security research, and news.
Latest analysis of npm/PyPI/cargo registry compromises, dependency confusion, and self-replicating worms (Shai-Hulud).
Malicious code in postcss-minify-selector-parser (npm)
Malicious code in jextic-eclib (npm)
Malicious code in pantheon-agents (PyPI)
Malicious code in nagios-xi (PyPI)
Malicious code in bramin (PyPI)
Malicious code in vite-svgr (npm)
Malicious code in ttspc-server-sample (npm)
Malicious code in ts-build-optimize (npm)
Malicious code in swagger-express-routes (npm)
Malicious code in sass-formats (npm)
Malicious code in nolimit-x (npm)
Malicious code in mcp-server-sentry (npm)
Malicious code in mcp-server-redis (npm)
Malicious code in mcp-server-postgres (npm)
Malicious code in mcp-server-notion (npm)
Malicious code in mcp-server-git (npm)
Malicious code in mcp-server-fetch (npm)
Malicious code in mcp-server-github (npm)
Malicious code in @emcd-vue/loans (npm)
Malicious code in @emcd-vue/b2b-pay-form (npm)
Malicious code in @emcd-vue/auth (npm)
Malicious code in @ikyyofc/gemini-cli (npm)
Malicious code in ecto-win-flag-q2m7 (npm)
Malicious code in ecto-spectral-leak-8d4e2 (npm)
Malicious code in ecto-rust-read-f3a9c1 (npm)
Malicious code in ecto-nightly-spirit (npm)
Malicious code in ect-472839 (npm)
Malicious code in chai-net-test (npm)
Malicious code in cdk-insights (npm)
Malicious code in chai-as-init (npm)
Malicious code in @sql-access/nodesql (npm)
ASUS Live Update Embedded Malicious Code Vulnerability
IPAM controller service account granted unnecessary full access to Secrets
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SimpleTrustManagerFactory.engineGetTrustManagers() and related paths wrap any user-supplied plain X5
MCP Server Kubernetes: kubectl-generic flag injection enables Kubernetes bearer token exfiltration
DevGuard has improper authorization on public assets
BoxLite: Permission Bypass Allows Modification of Read-Only Files
Malicious code in sn-internal-testjgsakjdkjadkjahsdkjad (npm)
LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, hardcoded "trust_remote_code=True" enables HF supply-chain RCE without user opt-in. At time of publication, there are no publ
Malicious code in sendgrid-sdk (npm)
Malicious code in gpt-sdk (npm)
Malicious code in nim-submit-for-test (npm)
Malicious code in @solana-labs/web3-js (npm)
Malicious code in bittensor-burn-watch (PyPI)
Malicious code in express-timer (npm)
Malicious code in express-self-destruct2 (npm)
Malicious code in janus-ft (npm)
Malicious code in @monitoring-lib/error-tracking (npm)
Malicious code in zer0onedatetool (npm)
vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors