#OpenSource used to mean trusting skilled developers to build and maintain good #software so others did not need to learn every language, tool, or best practice themselves.

Now, #SupplyChainAttack and #AISlop have made many projects harder to trust.

Too much software is rushed, poorly understood, or built for hype instead of quality.

#Developers now spend more time checking code, #dependencies, and #maintainers instead of simply building software.

#AI was supposed to reduce cognitive load๐Ÿ˜’

Popular node-IPC NPM package compromised to steal credentials

Node.js์˜ ์ธ๊ธฐ IPC ํŒจํ‚ค์ง€ node-ipc๊ฐ€ ์ตœ๊ทผ ๊ณต๊ธ‰๋ง ๊ณต๊ฒฉ์œผ๋กœ ์•…์„ฑ ์ฝ”๋“œ์— ๊ฐ์—ผ๋˜์–ด AWS, Azure, GCP ๋“ฑ ํด๋ผ์šฐ๋“œ ์ž๊ฒฉ ์ฆ๋ช…๊ณผ SSH ํ‚ค, CI/CD ๋น„๋ฐ€ ์ •๋ณด ๋“ฑ์„ ํƒˆ์ทจํ•˜๋Š” ์ •๋ณด ํƒˆ์ทจ ์•…์„ฑ์ฝ”๋“œ๊ฐ€ ํฌํ•จ๋œ ๋ฒ„์ „์ด ๋ฐฐํฌ๋๋‹ค. ๊ณต๊ฒฉ์ž๋Š” ๋น„ํ™œ์„ฑ ์œ ์ง€๊ด€๋ฆฌ์ž์˜ ๊ณ„์ •์„ ํƒˆ์ทจํ•ด ์•…์„ฑ ์ฝ”๋“œ๋ฅผ ์‚ฝ์ž…ํ–ˆ์œผ๋ฉฐ, DNS TXT ์ฟผ๋ฆฌ๋ฅผ ์ด์šฉํ•ด ๋ฐ์ดํ„ฐ๋ฅผ ์€๋ฐ€ํžˆ ์™ธ๋ถ€๋กœ ์ „์†กํ•œ๋‹ค. ๊ฐ์—ผ๋œ ๋ฒ„์ „์„ ์‚ฌ์šฉํ•˜๋Š” ๊ฐœ๋ฐœ์ž๋Š” ์ฆ‰์‹œ ํ•ด๋‹น ๋ฒ„์ „์„ ์ œ๊ฑฐํ•˜๊ณ  ๋…ธ์ถœ๋œ ๋น„๋ฐ€ ์ •๋ณด๋ฅผ ๊ต์ฒดํ•ด์•ผ ํ•œ๋‹ค.

https://www.bleepingcomputer.com/news/security/popular-node-ipc-npm-package-compromised-to-steal-credentials/

#security #supplychainattack #npm #nodejs #malware

Popular node-ipc npm package compromised to steal credentials

Hackers have injected credential-stealing malware into newly published versions of node-ipc, a popular inter-process communication package, in a new supply chain attack targeting npm.

BleepingComputer
๐Ÿšจ Breaking news! ๐Ÿšจ A supply chain attack on #npm shocks #developers worldwide, and in an utterly predictable twist, the only package manager where this "regularly happens" shrugs and says, "Oops, our bad." ๐Ÿ˜… Devs are now collectively wringing their hands, wondering how they got #bamboozled by the same trick for the zillionth time. ๐Ÿคฆโ€โ™‚๏ธ
https://kevinpatel.xyz/posts/no-way-to-prevent-this/ #supplychainattack #security #shocked #oops #HackerNews #ngated
โ€˜No Way To Prevent This,โ€™ Says Only Package Manager Where This Regularly Happens | Kevin Patel

Kevin Patel - Application Security Engineer @ NISC

Kevin Patel

AI took centre stage in cybersecurity this week on both sides of the battlefield. Critical zero-days to open-sourced malware, thereโ€™s plenty keeping security teams on high alert.

#AIinCybersecurity #ZeroDayExploit #SupplyChainAttack #DataBreach

https://cybernewsweekly.substack.com/p/cybersecurity-news-review-week-20-191

Cybersecurity News Review - Week 20 (2026)

AI took centre stage in cybersecurity this week - on both sides of the battlefield.

Cybersecurity News Weekly

OpenAI Breach Exposes Code-Signing Certificates in TanStack Supply Chain Attack

OpenAI revealed that two employee devices were compromised in a recent TanStack supply-chain attack, but fortunately, customer data, production systems, and intellectual property remained safe. The breach was limited to a small set of internal source code repositories and credentials.

https://osintsights.com/openai-breach-exposes-code-signing-certificates-in-tanstack-supply-chain-attack?utm_source=mastodon&utm_medium=social

#TanstackSupplyChain #Openai #CodesigningCertificates #SupplyChainAttack #EmergingThreats

OpenAI Breach Exposes Code-Signing Certificates in TanStack Supply Chain Attack

OpenAI breach exposes code-signing certificates in TanStack supply chain attack, learn how two employee devices were compromised and what it means for cybersecurity, read more now.

OSINTSights
#Socket detected a #supplychainattack on 84 #TanStack #npm packages, including popular ones like tanstack/react-router, which were compromised with suspected credential-stealing malware. The attack involved a chained #GitHub Actions attack and resulted in the publication of malicious packages authenticated through the projectโ€™s #OIDC trusted-publisher binding. https://socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack?eicker.news #tech #media #news
TanStack npm Packages Compromised in Ongoing Mini Shai-Hulud Supply-Chain Attack

Socket detected 84 compromised TanStack npm package artifacts modified with suspected CI credential-stealing malware.

Socket

An official Checkmarx Jenkins package was compromised with an infostealer. Trusted CI/CD pipelines are becoming prime supply-chain targets. Build security must start at the source. ๐Ÿ› ๏ธโš ๏ธ #SupplyChainAttack #DevSecOps

https://www.bleepingcomputer.com/news/security/official-checkmarx-jenkins-package-compromised-with-infostealer/

Official CheckMarx Jenkins package compromised with infostealer

Checkmarx warned over the weekend that a rogue version of its Jenkins Application Security Testing (AST) plugin had been published on the Jenkins Marketplace.

BleepingComputer

TeamPCP has open sourced their Shai-Hulud project.

It can be downloaded here.

https://vx-underground.org/tmp

#cybersecurity #infosec #teampcp #shaihuludmalware #supplychainattack

RubyGems Under Attack

RubyGems๊ฐ€ ํ˜„์žฌ ๋Œ€๊ทœ๋ชจ ์•…์„ฑ ๊ณต๊ฒฉ์„ ๋ฐ›๊ณ  ์žˆ์–ด ์‹ ๊ทœ ํšŒ์› ๊ฐ€์ž…์ด ์ผ์‹œ ์ค‘๋‹จ๋œ ์ƒํƒœ์ž…๋‹ˆ๋‹ค. ์ˆ˜๋ฐฑ ๊ฐœ์˜ ํŒจํ‚ค์ง€๊ฐ€ ๊ณต๊ฒฉ์— ์—ฐ๋ฃจ๋˜์—ˆ์œผ๋ฉฐ, ์ผ๋ถ€๋Š” ์•…์„ฑ ์ฝ”๋“œ๋ฅผ ํฌํ•จํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. RubyGems ํŒ€์€ ๊ณต๊ฒฉ ์ฐจ๋‹จ๊ณผ ๋ฐ์ดํ„ฐ ๋ถ„์„์„ ์œ„ํ•ด ๊ธด๊ธ‰ ๋Œ€์‘ ์ค‘์ด๋ฉฐ, DDoS ๋ฐ ์•…์„ฑ ์—…๋กœ๋“œ๋ฅผ ์ฐจ๋‹จํ•˜๋Š” ๋ฐ ์„ฑ๊ณตํ–ˆ์Šต๋‹ˆ๋‹ค. ์ปค๋ฎค๋‹ˆํ‹ฐ๋Š” ์ƒํ™ฉ์„ ์˜ˆ์˜์ฃผ์‹œํ•˜๋ฉฐ ์ถ”๊ฐ€ ์ •๋ณด๋ฅผ ๊ธฐ๋‹ค๋ฆฌ๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.

https://twitter.com/maciejmensfeld/status/2054164602577940619

#rubygems #supplychainattack #security #malware #opensource

Maciej Mensfeld (@maciejmensfeld) on X

We're dealing with a major malicious attack on @rubygems right now. Signups are paused for the time being. Hundreds of packages involved - mostly targeting us, but some carrying exploits. The team has been on this for hours. More details to follow once we're through it. #ruby

X (formerly Twitter)
TanStack npm Packages Compromised in Ongoing Mini Shai-Hulud Supply-Chain Attack

Socket detected 84 compromised TanStack npm package artifacts modified with suspected CI credential-stealing malware.

Socket