Skip to content
Open Source Beat
Explainers Open Source Projects Developer Tools Programming Languages
DevOps & Infrastructure AI & Machine Learning Security & Privacy Community & Governance Cloud & Databases

#supply-chain-attack

Abstract representation of code lines being breached or corrupted
Security & Privacy

GitHub Breach: VS Code Extension Compromise

A single malicious VS Code extension has led to a major breach at GitHub, compromising thousands of internal repositories. This incident underscores the escalating risks within the developer ecosystem.

5 min read an hour ago
Diagram illustrating the TanStack supply chain attack vector via GitHub Actions.
Security & Privacy

TanStack Attack: 42 Packages Compromised

Six minutes. That’s how long it took a relentless attacker to inject malicious code into 42 npm packages, a brazen display of how vulnerable our trusted open-source supply chains have become. TanStack is out with the nitty-gritty, and it’s not pretty.

5 min read 1 week, 6 days ago
Illustration of a digital lock being broken, symbolizing a security breach in software.
Security & Privacy

[WARNING] Popular OSS Package Stole User Credentials

So, your meticulously crafted open-source project, the one millions of devs rely on, just got hijacked to swipe credentials. Forget bug fixes for a second; this is about trust.

5 min read 2 weeks, 6 days ago
Warning alert on npmjs.com showing compromised axios package versions
Security & Privacy

Axios npm Package Serves Up RATs: The Two-Hour Nightmare That Could've Been Yours

Imagine your build server phoning home to hackers. Axios, with 100M+ weekly downloads, just lived that horror for two hours.

4 min read 1 month, 3 weeks ago
Illustration of a Cargo crate exploding with filesystem permission changes in Rust toolchain
Security & Privacy

Cargo's Hidden Tar Bomb: Malicious Crates That Could Own Your Filesystem

Imagine trusting Cargo to unpack a crate, only for it to stealthily escalate permissions across your drive. That's the nightmare CVE-2026-33056 unleashes on Rust builders.

5 min read 1 month, 3 weeks ago
Broken chain link with LiteLLM logo and malware code overlay
Cloud & Databases

LiteLLM's PyPI Poison: Trivy Scanner Turns Spy in Supply Chain Sneak Attack

Two LiteLLM releases yanked from PyPI after hackers hijacked Trivy to steal tokens and inject malware. Open source's dirty secret: your trusted tools might be the weakest link.

5 min read 1 month, 3 weeks ago
🔒
Security & Privacy

36 Fake Strapi Plugins Poison npm, Steal Guardarian Wallets

Npm's supply chain just took another hit—36 malicious packages posing as Strapi plugins, laser-focused on draining Guardarian wallets. Developers, wake up: this isn't random.

5 min read 1 month, 3 weeks ago
Abstract visualization of hidden code layered beneath visible legitimate source code, with Unicode characters highlighted
Security & Privacy

Invisible Code Is Now Flooding GitHub. Your Code Review Won't Catch It.

A new supply-chain attack is hiding malicious code in plain sight using invisible Unicode characters. Traditional defenses? Completely useless.

6 min read 1 month, 4 weeks ago

Categories

Explainers Open Source Projects Developer Tools Programming Languages DevOps & Infrastructure AI & Machine Learning Security & Privacy Community & Governance
Open Source Beat

Community-driven. Code-first.

More

  • RSS Feed
  • Sitemap
  • About
  • Editorial Process
  • Advertise

Legal

  • Privacy
  • Terms
  • Work With Us

Our Network

The AI Catchup AI & Machine Learning Threat Digest Cybersecurity Legal AI Beat Legal Tech Fintech Rundown Finance & Banking DevTools Feed Developer Tools Open Source Beat Open Source Fintech Dose Crypto & DeFi Chip Beat Semiconductors AdTech Beat Ad Technology Supply Chain Beat Logistics

© 2026 Open Source Beat. All rights reserved.

🏠Home 🔍Search 🔖Saved 📂Categories
Privacy & cookies

We use a privacy-respecting analytics tool to count page views — no personal profiles, no ad tracking, no third-party cookies. Accept to help us understand which stories matter to readers.

Details