Trainline : Search, Compare & Buy Cheap Train Tickets

package security

Travis Gettys is a senior editor for Raw Story based in northern Kentucky. Monthly newsletter focusing on open source cybersecurity tools This executes a 4.2 MB obfuscated payload automatically during every npm install, before any application code runs. According to Aikido and JFrog detections, the malicious packages were published via GitHub Actions OIDC tokens, indicating the CI/CD pipeline itself was compromised, not individual developer accounts.

And that’s why Vivint customers can’t live without their smart home systems. Take our How Secure Is Your Home quiz to learn more on why you need a smart home security system. Most DIY systems make you handle emergencies on your own. By accessing this blog, you agree to these terms and acknowledge your sole responsibility to verify and use the information as appropriate for your needs. Zscaler assumes no responsibility for any errors or omissions or for any actions taken based on the information provided. Attackers are using fake “leaked Claude” GitHub repositories to distribute a dual payload of Vidar Infostealer (for credential theft) and GhostSocks Malware (for network proxying).

  • Vivint’s standard HomeProtect package includes 1 Vivint Security Hub, 3 Vivint Door & Window Sensors, 1 Vivint Motion Sensor, 1 Vivint Keypad, and 1 Vivint yard sign.
  • Our U.S.-based team knows your neighborhood and your needs.
  • “It is the expansion of the campaign into another legitimate open source maintainer scope, this time involving Backstage plugins that sit close to internal developer portals, source-control integrations, and authentication workflows.”
  • Aqua Security’s Trivy, one of the most widely used open-source vulnerability scanners, was compromised in a multi-phase supply chain attack.
  • Most DIY systems make you handle emergencies on your own.
  • Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments.

Within an hour, more than 50 additional packages belonging to the maintainer jagreehal were also poisoned, including ai-sdk-ollama, which counts more than 120,000 monthly downloads. By submitting this form, I understand my personal data will https://master-your-business.com/what-role-does-technology-play-in-innovation/ be processed in accordance with Palo Alto Networks Privacy Statement and Terms of Use. From CI/CD misconfiguration detection to runtime behavioral threat detection and anomaly detection, every phase of the Trivy attack maps to a Cortex Cloud capability that detects or blocks it. Cortex Cloud’s integrated platform delivers layered defense across the full spectrum of supply chain attacks. It reminds us that security tools are high-value targets, mutable references like version tags create systemic vulnerabilities, and static analysis alone cannot detect attacks operating at application and network layers.

Home automation companies

Monitor build hosts and runners for unexpected package manager calls, network egress during build steps, and creation of suspicious systemd units or eBPF objects. For any host where the malicious payload may have run as root, treat it as compromised. Rebuild highly trusted systems.

Potential Misuse and Security Risks

Vivint’s standard HomeProtect package includes 1 Vivint Security Hub, 3 Vivint Door & Window Sensors, 1 Vivint Motion Sensor, 1 Vivint Keypad, and 1 Vivint yard sign. Our U.S.-based team knows your neighborhood and your needs. Read more about why Vivint customers love their smart home security systems.

package security

This makes reinfected packages appear fully legitimate even to tools specifically designed to verify supply chain integrity. When the Shai-Hulud malware first appeared in the npm space in mid-September, and it compromised 187 packages with a self-propagating payload that used the TruffleHog tool to steal developer secrets. Learn how to secure AI agents with practical controls for access, visibility, secrets, and risk containment. Find out the cost of smart home automation in 2026, including devices, installation, and which options make sense for your home.

package security

Attackers targeted packages with existing users and a history of legitimate use. Share code, explore data, write, and learn across your apps in ways you couldn’t before. Catalog of official Microsoft MCP (Model Context Protocol) server implementations for AI-powered data access and tool integration This incident echoes a growing trend of supply chain attacks targeting package repositories across ecosystems. These packages https://texas-news.com/animated-explainers-for-the-tech-and-software-sectors.html acted as the primary malware delivery mechanism, executing during the standard package build process without triggering obvious warnings to end users. The threat actors systematically targeted orphaned AUR packages legitimate projects that have been abandoned by their original maintainers and claimed ownership of them through AUR’s standard adoption process.

  • The self-replicating cryptographic verification of the malicious packages and the ability to bypass hash-based detection make the attacks difficult to detect.
  • These packages acted as the primary malware delivery mechanism, executing during the standard package build process without triggering obvious warnings to end users.
  • Active shooters, vehicle ramming, improvised explosive devices (IEDs), unmanned aircraft systems (UASs), and many more.
  • It appears that the threat actor has also gained access to GitHub accounts that they are now using to create repositories with the four files above.
  • A power 6.2L V8 is standard and a 6.2L Supercharged V8 as optional

The attackers hijacked a legitimate, trusted npm namespace and published backdoored versions of widely-used frontend components, API clients, and developer tooling. A significant supply chain attack on June 1, 2026, targeting over 30 official packages under the @redhat-cloud-services npm scope. Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks. Aikido Security advises developers to disable npm postinstall scripts during continuous integration, if possible. Wiz researchers recommend security teams to first identify the compromised packages and replace them with legitimate ones. Developers are advised to check Aikido’s post for the complete list of the infected packages, downgrade to safe versions, and rotate their secrets and CI/CD tokens immediately.

Leave a Reply

Your email address will not be published. Required fields are marked *