Lyrie
← Home

#supply-chain

99 stories tagged.

OpenAI Got Hit by a Supply Chain Attack. Lyrie Would Have Stopped It Before It Started.

9 min · 4 sources

Next-Gen Supply Chain Poisoning: CVE-2026-23550 WordPress Plugin Attack and How LLM-Based Intent Analysis Caught It

9 min · 3 sources

The Zero-Day Supply Chain: How Lyrie Caught 7 Backdoors Before Public Disclosure

10 min · 3 sources

The Worm That Learned to Sign Itself: Shai Hulud's Eight-Month npm Supply Chain Rampage — A Full Post-Mortem

12 min · 0 sources

The CI/CD Takeover: How GitHub Actions Script Injection Turned elementary-data Into a 1.1M-Download Infostealer

9 min · 0 sources

The JDownloader Watering Hole: How a CMS Zero-Day Turned 10 Million Download Links Into a Python RAT Delivery Network

8 min · 0 sources

The Mother of All AI Supply Chains: MCP's Architectural RCE Flaw and What It Means for Every AI Agent You Deploy

9 min · 0 sources

QLNX: The Developer-Hunting Linux RAT That Turns Package Maintainers into Supply Chain Weapons

10 min · 0 sources

The Flippa Gambit: How a Six-Figure Marketplace Purchase Backdoored 400,000 WordPress Sites—and Why Blockchain C2 Changes Everything

11 min · 0 sources

The Poisoned Model Registry: How Hugging Face Became the AI Era's Most Dangerous Software Distribution Channel

11 min · 0 sources

The Trusted Installer Trap: DAEMON Tools Supply Chain Attack Delivers QUIC RAT to Government, Manufacturing Targets

9 min · 0 sources

The Rigged Game: ScarCruft / APT37 Threat Actor Profile — From RokRAT to BirdCall, North Korea's Quietest Hunter Upgrades Its Arsenal

10 min · 0 sources

The Marketplace Is the Attack Surface: How 'Trust Inheritance' Became 2026's Most Dangerous Supply Chain Vector

12 min · 0 sources

When the AI Writes the Backdoor: PromptMink, Famous Chollima, and the Dawn of LLMO-Optimized Supply Chain Attacks

11 min · 0 sources

Developer Machines Are the New Supply Chain Perimeter: QLNX and DAEMON Tools Reveal a Bifurcated Attack Model

11 min · 0 sources

The Worm That Eats Developers: Shai-Hulud's Third Coming and the Mini Wave That Hit 1,800 Repos in 48 Hours

10 min · 0 sources

The Developer Is the New Perimeter: How QLNX and Shai-Hulud Are Turning Developer Workstations Into Supply Chain Launchpads

11 min · 0 sources

Signed, Sealed, Delivered Malware: The DAEMON Tools Supply Chain Attack and the QUIC RAT That Followed

9 min · 0 sources

Buy, Wait, Detonate: The Essential Plugin Flippa Acquisition Supply Chain Attack and the Blockchain C2 That Made It Unstoppable

12 min · 0 sources

The Worm That Reads Your Secrets: Shai-Hulud, QLNX, and the 2026 Developer Credential Supply Chain War

9 min · 0 sources

The Worm That Eats Your Vault: Shai-Hulud's Bitwarden CLI Attack and the Definitive CI/CD Secrets Defense Playbook

11 min · 0 sources

The Trusted Installer Lie: DAEMON Tools Supply Chain Compromise and the QLNX Linux RAT Expose 2026's Deadliest Attack Pattern

9 min · 0 sources

The Instruction File Is the Weapon: How 'DeepSeek-Claw' Turned Agentic AI Into a Self-Executing Attack Chain

8 min · 0 sources

The npm Trust Stack Is Broken: Axios DPRK Compromise, DevTap Persistence Implant, and EVM/DeFi Key Theft — A 2026 Supply Chain Post-Mortem Trifecta

11 min · 0 sources

The Signed Installer Trap: DAEMON Tools Supply Chain Compromise Delivers QUIC RAT to Government & Manufacturing Targets

11 min · 0 sources

When the Framework Is the Vulnerability: Semantic Kernel RCE, MCP's Architectural Flaw, and the Collapse of the AI Agent Trust Boundary

11 min · 0 sources

Pipeline Poisoners: How BufferZoneCorp Weaponized Ruby Gems and Go Modules to Own CI/CD at the Build Stage

10 min · 0 sources

Worm Logic: TeamPCP's Shai-Hulud 'Third Coming' Compromises Bitwarden CLI and 796 npm Packages — A Full Post-Mortem

10 min · 0 sources

The Worm That Crossed the Ecosystem: Mini Shai-Hulud's PyTorch Lightning Hijack and the Rise of Cross-Registry Supply Chain Attacks

10 min · 0 sources

The Official Installer Trap: DAEMON Tools Supply Chain Attack — A Month of Signed Malware, QUIC RAT, and a Ghost C2

9 min · 0 sources

The Third Layer: How AI Agent Skill Ecosystems Became the Supply Chain That No Scanner Can See

9 min · 0 sources

The Crypto Dev Trap: Six Fake npm Packages Target EVM Engineers, Drain Wallets and Cloud Credentials in Real Time

8 min · 0 sources

The 11-Hour Data Heist: How a GitHub Actions PR Comment Poisoned 1.1M-Download PyPI Package elementary-data

9 min · 0 sources

The 42-Minute Worm: TeamPCP's Mini Shai-Hulud Tears Through PyTorch, SAP, and Intercom in 48 Hours

9 min · 0 sources

The 90-Minute Window: How Shai-Hulud's Third Coming Weaponized Bitwarden's Own CI Pipeline Against 250,000 Developers

10 min · 0 sources

The Developer Machine as Rental Infrastructure: How kube-health-tools Turned Kubernetes Engineers Into Chinese LLM Relay Nodes

8 min · 0 sources

Attacking the Watchers: How TeamPCP Weaponized Trivy, Checkmarx, and Bitwarden CLI Against the Entire Developer Ecosystem

10 min · 0 sources

The Data Pipeline That Became a Drain: How elementary-data's CI/CD Was Weaponized to Steal 1.1M-Download-Scale Cloud Credentials

9 min · 0 sources

Locking Down the AI Stack: A 2026 Defender's Playbook for LLM Infrastructure

11 min · 0 sources

\"A Mini Shai-Hulud Has Appeared\": How Attackers Turned SAP's npm Ecosystem Into a Credential Vacuum

9 min · 0 sources

The Protocol That Became the Weapon: MCP Tool Poisoning, Adversarial ML, and the Client-Side Attack Class Breaking Every AI Agent You Deploy

11 min · 0 sources

The Worm That Won't Stop: TeamPCP's Mini Shai-Hulud Supply Chain Campaign Devours SAP, Bitwarden, and PyTorch Lightning

9 min · 0 sources

The Comment That Poisoned a Million Pipelines: elementary-data's GitHub Actions Script Injection and the Rise of CI-Native Supply Chain Attacks

10 min · 0 sources

Shai-Hulud Devours the Ecosystem: TeamPCP's Cross-Ecosystem Supply Chain Blitz Hits PyTorch Lightning, SAP npm, Bitwarden, and Hundreds of CI/CD Pipelines

8 min · 0 sources

The IDE That Eats Itself: GlassWorm v2's Sleeper Extensions, Zig Dropper, and Cross-IDE Takeover of 50,000 Developer Machines

9 min · 0 sources

The Pipeline Is the Payload: How GitHub Actions Script Injection Turned elementary-data Into a Credential Harvester for 1.1 Million Developers

11 min · 0 sources

The Worm That Rode the Sandstorm: Mini Shai-Hulud's TeamPCP Supply Chain Assault Across PyPI, npm, and PHP

10 min · 0 sources

The Diagnostic Tool Became the Implant: How the CityOfSin Campaign Turned CPUID Downloads Into a Six-Hour STX RAT Deployment Window

11 min · 0 sources

The Package That Waited: BufferZoneCorp's Sleeper Gems and Go Modules Reveal a New CI Pipeline Takeover Playbook

9 min · 0 sources

Shai-Hulud: The Third Coming — How TeamPCP Turned Trivy Into a Master Key, Checkmarx Into a Staging Ground, and Bitwarden CLI Into a Self-Propagating CI/CD Worm

10 min · 0 sources

The Pipeline Is the Weapon: How elementary-data's GitHub Actions Injection Turned 1.1 Million PyPI Installs Into a Credential Vacuum

11 min · 0 sources

The Worm That Reads the Room: TeamPCP's Mini Shai-Hulud Crosses the PyPI/npm Divide and Poisons AI Infrastructure

10 min · 0 sources

Your AI Coding Agent Is the Attacker Now: CVE-2026-26268, the Gemini CLI CVSS 10, and Why the Developer Toolchain Is 2026's Hottest Attack Surface

10 min · 0 sources

The Butlerian Jihad Post-Mortem: How TeamPCP Turned Bitwarden Into an npm Worm That Poisons AI Coding Assistants

11 min · 0 sources

The Agent Became the Weapon: PromptMink, a16z's DeFi Exploit Research, and the Autonomous Trading Agent Attack Surface

11 min · 0 sources

The Protocol Is the Payload: MCP's STDIO Flaw, Tool Poisoning, and the 150-Million-Download Time Bomb

11 min · 0 sources

The Sleeper Cluster Wakes: BufferZoneCorp + TeamPCP's Cross-Ecosystem Supply Chain Wave (Ruby, Go, npm, GitHub Actions)

11 min · 0 sources

The AI Framework Trojan: How PyTorch Lightning's PyPI Compromise Became the Most Dangerous Supply Chain Attack of 2026

11 min · 0 sources

The Incomplete Patch Trilogy: Apache MINA's Deserialization Crisis and the Allowlist That Wasn't (CVE-2026-42779, CVE-2026-42778, CVE-2026-41635)

10 min · 0 sources

The AI Agent Toolchain Is the New Kill Zone: CanisterSprawl's Post-Mortem

11 min · 0 sources

When the Scanner Gets Scanned: How TeamPCP Turned Security Tools Into the Attack Surface — A Full Post-Mortem of the Trivy→Checkmarx→Bitwarden Cascade

12 min · 0 sources

The AI Accomplice: How North Korea's Famous Chollima Used Claude Opus to Plant Malware in Crypto Trading Agents

9 min · 0 sources

The Worm That Codes Itself: TeamPCP's Mini Shai-Hulud and the Industrialization of Open-Source Supply Chain Attacks

11 min · 0 sources

The AI Infrastructure Trust Crisis: How the Tools That Build AI Became the Biggest Attack Surface of 2026

10 min · 0 sources

One git push to Own GitHub: The X-Stat Header Injection Behind CVE-2026-3854

9 min · 0 sources

The Worm That Crossed the Ocean: Mini Shai-Hulud, TeamPCP, and the Supply Chain Attack That Won't Stop Evolving

11 min · 0 sources

Amateur Hour at the Ransomware Factory: VECT's Broken Crypto, BreachForums Army, and the Accidental Wiper Nobody Can Decrypt

10 min · 0 sources

The Trust Inversion: How TeamPCP Turned Your Security Scanner Into a CI/CD Master Key

10 min · 0 sources

One Push to Own Them All: CVE-2026-3854 and the Injection Flaw Inside GitHub's git Pipeline

9 min · 0 sources

The Protocol That Trusted Everyone: MCP's Architecture-Level Security Crisis, 200,000 Exposed Instances, and the AI Supply Chain Nobody Patched

13 min · 0 sources

The Worm That Cannot Be Killed: CanisterSprawl, Blockchain C2, and the Self-Propagating Supply Chain Nightmare

12 min · 0 sources

The CI/CD Killswitch: GitHub Actions' Systemic Design Flaws and the Eighteen-Month Chain from spotbugs to Bitwarden

10 min · 0 sources

The Agent Removed the Human: Prompt Injection, Git Hooks, and the Collapse of the Developer Workstation Perimeter

9 min · 0 sources

The Password Manager Was the Payload: Shai-Hulud v3, the Triple-Registry Storm, and the Collapse of Developer Trust

11 min · 0 sources

The Protocol That Runs Everything and Trusts Everything: MCP's STDIO Architectural Flaw and the 200,000 AI Servers That Inherited It

12 min · 0 sources

The Guardians Were Already Compromised: TeamPCP's Second Checkmarx Strike and the April 2026 Triple-Registry Credential Harvest

9 min · 0 sources

The Fortune 500 Faker: How Attackers Impersonated Asurion's npm Packages to Run a Multi-Stage Credential Harvester

11 min · 0 sources

The Worm That Lives on the Blockchain: CanisterSprawl's ICP C2 Architecture and the 48-Hour Supply Chain Blitz That Broke Three Ecosystems

10 min · 0 sources

Hacking the Hunters: How TeamPCP Turned Security Tooling Into the Supply Chain Weapon

10 min · 0 sources

Comment and Control: How a PR Title Became a C2 Channel and Drained Secrets from Three AI Coding Agents

10 min · 0 sources

The Compromised Workbench: Definitive 2026 Defensive Playbook Against IDE Extension Supply Chain Attacks (GlassWorm + PAT Hijacking)

10 min · 0 sources

GlassWorm escalates: 73 Open VSX sleeper extensions deploy malware to VS Code, Cursor, and every VSIX IDE

11 min · 3 sources

The 100 Million Download Backdoor: A Full Post-Mortem of the Axios npm Supply Chain Compromise

8 min · 0 sources

11 ways agents get hijacked in 2026 — a defender's field guide

12 min · 18 sources

The Agentic Kill Chain: How MCP's Architectural RCE and In-the-Wild Prompt Injection Are Converging Into a New Attack Class

13 min · 0 sources

The 48-Hour Supply Chain Siege: Shai-Hulud, TeamPCP, and the Week the Developer Toolchain Became the Kill Chain

11 min · 0 sources

The Agentic Trojan: ClawHavoc, ClawJacked, and How AI Skill Marketplaces Became the Next Supply Chain Battleground

12 min · 0 sources

CanisterSprawl Post-Mortem: How npm's Self-Propagating Worm Weaponized Blockchain Infrastructure to Become Seizure-Proof

11 min · 0 sources

The Trust Ladder: How TeamPCP Climbed From Security Scanners to Password Managers — Six Weeks of Supply Chain Escalation, Post-Mortem

10 min · 0 sources

The Scanner That Got Scanned: Trivy's Double Breach, Hackerbot-Claw, and the AI-Automated Future of GitHub Actions Supply Chain Attacks

10 min · 0 sources

The Foundation Is the Vulnerability: How MCP's Architectural RCE Flaw Put 200,000 AI Servers at Risk

10 min · 0 sources

The 48-Hour Siege: How Three Simultaneous Supply Chain Campaigns Turned npm, PyPI, and Docker Hub Into Credential Factories

12 min · 0 sources

Comment and Control: How Prompt Injection Became a Production Exploit Across Every Major AI Coding Agent

12 min · 0 sources

The 174-Minute Poison Window: How North Korean Hackers Compromised 100 Million Weekly npm Downloads and Triggered the Vercel Breach

10 min · 0 sources

The Scanner That Scanned You Back: TeamPCP's Second Checkmarx Breach and the April 2026 Supply Chain Siege

13 min · 0 sources

Your Kubernetes Package Is Now an AI Piracy Node: The kube-health-tools GPT-Proxy Supply Chain Attack

9 min · 0 sources

CVE-2024-1709: ConnectWise ScreenConnect Supply Chain Breach Vector

3 min · 3 sources

The April 2026 Open Source Supply Chain Storm: Axios, CanisterWorm, and the 48-Hour Assault on npm, PyPI, and Docker Hub

10 min · 0 sources

Your AI Dev Stack Is the Attack Surface: CVE-2026-39987 (Marimo) and CVE-2026-5760 (SGLang) Signal a New Threat Class

10 min · 0 sources