ThreatPaper

#unattributed

3 cases

Excerpt For 33 hours an attacker rerouted the addresses Softaculous updates come from, obtained a genuine TLS certificate for the diverted domains, and served a malicious Virtualizor update that nothing in the chain was able to reject.

Supply Chain AttackMalware

A stranger emailed an unpaid maintainer offering to take over a package he no longer used. Three months later it was stealing private keys from bitcoin wallets holding more than 100 BTC. Nobody was ever identified.

Supply Chain AttackCryptocurrency & Web3

A credential left in a Docker image layer let an unidentified attacker rewrite Codecov's Bash Uploader and harvest every secret from its customers' CI environments for sixty days. No one was ever identified.

Supply Chain Attack