ThreatPaperBeta

#supply-chain

9 cases

A credential left in a Docker image layer let an unidentified attacker rewrite Codecov's Bash Uploader and harvest every secret from its customers' CI environments for sixty days. No one was ever identified.

Supply Chain Attack

A North Korean-linked actor compromised Trading Technologies' X_TRADER, used it to breach 3CX, and shipped signed, trojanised VoIP clients to its customers — the first documented case of one software supply chain attack causing another.

Supply Chain AttackState-Sponsored

Between late 2025 and mid-2026, the software supply chain threat landscape underwent a fundamental paradigm shift with the emergence of the Shai-Hulud malware lineage. Culminating in the highly...

MalwareSupply Chain Attack

Between mid-2025 and August 2026, a cybercriminal collective operating primarily under the ShinyHunters brand—alongside associated activity clusters tracked as UNC6040, UNC6240, UNC6395, UNC6661, and...

Data BreachSupply Chain Attack

Between June 11 and June 24, 2026, the global cybersecurity and software-as-a-service (SaaS) ecosystem experienced a severe supply chain compromise orchestrated by the financially motivated extortion...

Data Breach

On August 20, 2026, attackers hijacked a prominent Rust ecosystem crate and pushed a malicious update to `arrayref@0.3.10`, a small array-conversion utility with approximately 245 million lifetime...

Supply Chain Attack

Attackers compromised a GitHub Personal Access Token belonging to the `tj-actions-bot`, retroactively rewriting version tags v1–v45.0.7 of the widely-used `tj-actions/changed-files` Action to point to a malicious commit. The payload scanned runner memory for secrets and printed them directly into public workflow logs, exposing CI/CD credentials across 23,000+ repositories. Tracked as CVE-2025-30066; linked to an earlier compromise of `reviewdog/action-setup@v1` (CVE-2025-30154).

Supply Chain Attack

The BlackSuit ransomware group (a rebrand of Royal Ransomware) compromised CDK Global, the dominant Dealer Management System provider for North American auto dealerships, causing a weeks-long outage affecting ~15,000 dealerships' ability to sell, finance, service, and manage vehicles — one of the most disruptive ransomware incidents against a critical software supplier in 2024.

Ransomware

A sophisticated multi-year supply chain attack compromised the widely used xz compression library, embedding a backdoor in liblzma that targeted OpenSSH authentication on systemd-based Linux distributions. The attacker, operating under the persona 'Jia Tan,' spent over two years building trust as a contributor before gaining maintainership and inserting the malicious code.

Supply Chain Attack