⤷ Title: TeamPCP Hijacks Checkmarx in Sprawling Supply Chain Strike
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:19:36 +0000
════════════════════════
⌗ Tags: #Malware #Checkmarx #Credential Theft #cybersecurity #docker #GitHub Actions #infosec #Malware Analysis #npm #supply chain attack #TeamPCP #VS Code
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:19:36 +0000
════════════════════════
⌗ Tags: #Malware #Checkmarx #Credential Theft #cybersecurity #docker #GitHub Actions #infosec #Malware Analysis #npm #supply chain attack #TeamPCP #VS Code
Daily CyberSecurity
TeamPCP Hijacks Checkmarx in Sprawling Supply Chain Strike
Checkmarx Docker images and VS Code extensions hijacked by TeamPCP to siphon cloud secrets and spread via npm. Audit your "Dune" repositories today.
⤷ Title: Supply Chain Sabotage: Bitwarden CLI Compromised in Global “Checkmarx” Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 01:41:43 +0000
════════════════════════
⌗ Tags: #Malware #Bitwarden #Bitwarden CLI #bw1.js #Checkmarx Campaign #cybersecurity #Dune Malware #GitHub Actions #infosec #malware #secret management #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 01:41:43 +0000
════════════════════════
⌗ Tags: #Malware #Bitwarden #Bitwarden CLI #bw1.js #Checkmarx Campaign #cybersecurity #Dune Malware #GitHub Actions #infosec #malware #secret management #supply chain attack
Daily CyberSecurity
Supply Chain Sabotage: Bitwarden CLI Compromised in Global "Checkmarx" Campaign
Bitwarden CLI v2026.4.0 compromised in "Dune"-themed supply chain attack. Malware steals cloud secrets and SSH keys. Rotate your credentials immediately.
⤷ Title: Patching the CVSS 10 RCE Hole in Gemini CLI
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 03:01:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #@google/gemini_cli #AI security #Automation #CI/CD security #CVSS 10 #Gemini CLI #GitHub Actions #infosec #Patch Alert #Prompt injection #rce
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 03:01:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #@google/gemini_cli #AI security #Automation #CI/CD security #CVSS 10 #Gemini CLI #GitHub Actions #infosec #Patch Alert #Prompt injection #rce
⤷ Title: The Poisoned Pipeline: How a GitHub Actions Flaw Infiltrated the Popular “Elementary-Data” Library
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 07:30:10 +0000
════════════════════════
⌗ Tags: #Malware #2026 Tech News #cloud security #Credential Stealer #Data Engineering #dbt #Docker #Elementary_data #GitHub Actions #GITHUB_TOKEN #PyPI #Python Security #supply chain attack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 07:30:10 +0000
════════════════════════
⌗ Tags: #Malware #2026 Tech News #cloud security #Credential Stealer #Data Engineering #dbt #Docker #Elementary_data #GitHub Actions #GITHUB_TOKEN #PyPI #Python Security #supply chain attack
Penetration Testing Tools
The Poisoned Pipeline: How a GitHub Actions Flaw Infiltrated the Popular "Elementary-Data" Library
The ubiquitous Python library elementary-data has emerged as a conduit for the exfiltration of sensitive developer telemetry. The
⤷ Title: Desert Power in the Code: How the “Mini Shai-Hulud” Malware Burrows into SAP’s npm Supply Chain
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 04 May 2026 07:44:09 +0000
════════════════════════
⌗ Tags: #Malware #@cap_js #CI/CD Security #CircleCI #cloud security #Credentials Theft #Cyber Security 2026 #GitHub Actions #malware #Mini Shai_Hulud #npm #SAP #supply chain attack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 04 May 2026 07:44:09 +0000
════════════════════════
⌗ Tags: #Malware #@cap_js #CI/CD Security #CircleCI #cloud security #Credentials Theft #Cyber Security 2026 #GitHub Actions #malware #Mini Shai_Hulud #npm #SAP #supply chain attack
Information Security News
Desert Power in the Code: How the "Mini Shai-Hulud" Malware Burrows into SAP’s npm Supply Chain
Adversaries have once again targeted the npm supply chain, though this incursion pursued a surgical and perilous objective:
⤷ Title: Supply Chains in the Crosshairs: Scan and Simulate Multi-Stage Attacks with Trajan
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 05 May 2026 08:24:29 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Azure DevOps #CI/CD Security #DevSecOps #GitHub Actions #GitLab CI #jenkins #JFrog #Pentesting Tools #supply chain attack #Taint Tracking #Trajan #WebAssembly
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 05 May 2026 08:24:29 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Azure DevOps #CI/CD Security #DevSecOps #GitHub Actions #GitLab CI #jenkins #JFrog #Pentesting Tools #supply chain attack #Taint Tracking #Trajan #WebAssembly
Penetration Testing Tools
Supply Chains in the Crosshairs: Scan and Simulate Multi-Stage Attacks with Trajan
Trajan isn't just a scanner. It maps dependency graphs and uses built-in attack plugins to simulate real-world CI/CD supply chain compromises.
⤷ Title: Supply Chain Siege: 84 TanStack Packages Compromised to Steal GitHub Secrets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 01:37:03 +0000
════════════════════════
⌗ Tags: #Malware #@tanstack/react_router #CI/CD security #credential stealer #GitHub Actions #infosec #JavaScript Security #Malware Analysis #npm Security #Socket Threat Research #supply chain attack #TanStack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 01:37:03 +0000
════════════════════════
⌗ Tags: #Malware #@tanstack/react_router #CI/CD security #credential stealer #GitHub Actions #infosec #JavaScript Security #Malware Analysis #npm Security #Socket Threat Research #supply chain attack #TanStack
Daily CyberSecurity
Supply Chain Siege: 84 TanStack Packages Compromised to Steal GitHub Secrets
Urgent: 84 TanStack npm packages hijacked to harvest GitHub Actions secrets. Over 12M weekly downloads impacted. Audit your CI/CD pipelines and rotate tokens.
⤷ Title: Urgent Update: Composer Vulnerability Leaks GitHub Secrets in Plaintext Logs (CVE-2026-45793)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:34:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD security #Composer #Credential Theft #CVE_2026_45793 #DevSecOps #GitHub Actions #GitHub Token #Information Disclosure #Nils Adermann #php
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:34:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD security #Composer #Credential Theft #CVE_2026_45793 #DevSecOps #GitHub Actions #GitHub Token #Information Disclosure #Nils Adermann #php
Daily CyberSecurity
Urgent Update: Composer Vulnerability Leaks GitHub Secrets in Plaintext Logs (CVE-2026-45793)
Composer CVE-2026-45793 leaks GitHub tokens into CI/CD logs due to a validation error. Update to version 2.9.8 now and audit your GitHub Action logs.
⤷ Title: Mini Shai-Hulud Alert: TeamPCP Hijacks @tanstack and PyPI to Poison 12 Million Weekly Downloads
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 08:12:28 +0000
════════════════════════
⌗ Tags: #Malware #@tanstack #GitHub Actions #InfoSec 2026 #Mini Shai_Hulud #npm security #OIDC #PyPI malware #supply chain attack #tanstack_runner.js #TeamPCP #Trusted Publishing
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 08:12:28 +0000
════════════════════════
⌗ Tags: #Malware #@tanstack #GitHub Actions #InfoSec 2026 #Mini Shai_Hulud #npm security #OIDC #PyPI malware #supply chain attack #tanstack_runner.js #TeamPCP #Trusted Publishing
Penetration Testing Tools
Mini Shai-Hulud Alert: TeamPCP Hijacks @tanstack and PyPI to Poison 12 Million Weekly Downloads
The Mini Shai-Hulud incursion has once again laid siege to the software supply chain. While the initial offensive
⤷ Title: The Trojan PR: Achieving Code Execution in GitHub Actions via Pipeline Poisoning
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
ⴵ Time: Fri, 15 May 2026 12:18:45 GMT
════════════════════════
⌗ Tags: #infosec #ethical_hacking #bug_bounty #github_actions #ci_cd_pipeline
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
ⴵ Time: Fri, 15 May 2026 12:18:45 GMT
════════════════════════
⌗ Tags: #infosec #ethical_hacking #bug_bounty #github_actions #ci_cd_pipeline
Medium
The Trojan PR: Achieving Code Execution in GitHub Actions via Pipeline Poisoning
Introduction
⤷ Title: The Trojan PR: Achieving Code Execution in GitHub Actions via Pipeline Poisoning
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
ⴵ Time: Mon, 18 May 2026 10:19:33 GMT
════════════════════════
⌗ Tags: #infosec #ethical_hacking #bug_bounty #github_actions #ci_cd_pipeline
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
ⴵ Time: Mon, 18 May 2026 10:19:33 GMT
════════════════════════
⌗ Tags: #infosec #ethical_hacking #bug_bounty #github_actions #ci_cd_pipeline
Medium
The Trojan PR: Achieving Code Execution in GitHub Actions via Pipeline Poisoning
Introduction
⤷ Title: Shai-Hulud Returns: Massive npm Supply Chain Attack Hijacks AntV Ecosystem to Scrape GitHub Runner Memory
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 06:52:05 +0000
════════════════════════
⌗ Tags: #Malware #AntV Ecosystem #atool #Claude Code Hijack #Cyber Security #GitHub Actions #infosec #Mini Shai_Hulud #npm Worm #Runner Memory Scraper #supply chain attack #timeago.js
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 06:52:05 +0000
════════════════════════
⌗ Tags: #Malware #AntV Ecosystem #atool #Claude Code Hijack #Cyber Security #GitHub Actions #infosec #Mini Shai_Hulud #npm Worm #Runner Memory Scraper #supply chain attack #timeago.js
Daily CyberSecurity
Shai-Hulud Returns: Massive npm Supply Chain Attack Hijacks AntV Ecosystem to Scrape GitHub Runner Memory
The Mini Shai-Hulud npm worm has hijacked the atool account, poisoning AntV & timeago.js to scrape GitHub runner memory. Execute a full reset now!
⤷ Title: Ecosystem Poisoned: Mini Shai-Hulud Worm Hijacks @antv npm Packages to Target CI/CD Pipelines
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 02:59:48 +0000
════════════════════════
⌗ Tags: #Malware #AntV Ecosystem #CI/CD Pipeline Security #Cyber Security #echarts_for_react #GitHub Actions Memory Scraping #infosec #Mini Shai_Hulud #npm Supply Chain Attack #Sigstore Forgery #TeamPCP #Token Theft
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 02:59:48 +0000
════════════════════════
⌗ Tags: #Malware #AntV Ecosystem #CI/CD Pipeline Security #Cyber Security #echarts_for_react #GitHub Actions Memory Scraping #infosec #Mini Shai_Hulud #npm Supply Chain Attack #Sigstore Forgery #TeamPCP #Token Theft
Daily CyberSecurity
Ecosystem Poisoned: Mini Shai-Hulud Worm Hijacks @antv npm Packages to Target CI/CD Pipelines
Microsoft warns of an aggressive Mini Shai-Hulud worm attack targeting the @antv npm ecosystem and stealing secrets from cloud-connected CI/CD pipelines.
⤷ Title: Malicious JS Lifecycle Hooks Found Hiding Inside PHP Composer Packages
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 23 May 2026 04:32:47 +0000
════════════════════════
⌗ Tags: #Malware #CI/CD Poisoning #Cross_Ecosystem Malice #Cyber Security #devdojo/wave #GitHub Actions Backdoor #infosec #package.json Exploit #PHP Composer #Postinstall Script #Socket Security #Starter Kits #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 23 May 2026 04:32:47 +0000
════════════════════════
⌗ Tags: #Malware #CI/CD Poisoning #Cross_Ecosystem Malice #Cyber Security #devdojo/wave #GitHub Actions Backdoor #infosec #package.json Exploit #PHP Composer #Postinstall Script #Socket Security #Starter Kits #supply chain attack
Daily CyberSecurity
Malicious JS Lifecycle Hooks Found Hiding Inside PHP Composer Packages
Socket exposes a clever cross-ecosystem supply chain attack targeting PHP packages by hiding a malicious JS postinstall backdoor inside package.json.
⤷ Title: The Shai-Hulud Infiltration: Red Hat Exploited in Sovereign Supply Chain Breach
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 02 Jun 2026 04:35:11 +0000
════════════════════════
⌗ Tags: #Malware #credential harvesting malware #GitHub Actions OIDC bypass #Mini Shai_Hulud worm #Red Hat NPM attack #supply chain compromise #trusted publishing vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 02 Jun 2026 04:35:11 +0000
════════════════════════
⌗ Tags: #Malware #credential harvesting malware #GitHub Actions OIDC bypass #Mini Shai_Hulud worm #Red Hat NPM attack #supply chain compromise #trusted publishing vulnerability
Daily CyberSecurity
The Shai-Hulud Infiltration: Red Hat Exploited in Sovereign Supply Chain Breach
Recently, several prominent cybersecurity corporations simultaneously intercepted a series of malicious software repositories. Specifically, an adversary uploaded these corrupted packages directly…
⤷ Title: Shift Security Left: Detecting Code Vulnerabilities Early with CodeQL in GitHub Actions
════════════════════════
𐀪 Author: SwayamOps
════════════════════════
ⴵ Time: Thu, 04 Jun 2026 05:36:39 GMT
════════════════════════
⌗ Tags: #shift_left_security #github_actions #application_security #codeql #devsecops
════════════════════════
𐀪 Author: SwayamOps
════════════════════════
ⴵ Time: Thu, 04 Jun 2026 05:36:39 GMT
════════════════════════
⌗ Tags: #shift_left_security #github_actions #application_security #codeql #devsecops
Medium
Shift Security Left: Detecting Code Vulnerabilities Early with CodeQL in GitHub Actions
Most CI pipelines are great at answering one question:
⤷ Title: Building a Parallel Security Gate in CI: Combining Secret Scanning, Dependency Audits, and SAST…
════════════════════════
𐀪 Author: SwayamOps
════════════════════════
ⴵ Time: Fri, 05 Jun 2026 05:58:28 GMT
════════════════════════
⌗ Tags: #cicd #application_security #github_actions #shift_left_security #devsecops
════════════════════════
𐀪 Author: SwayamOps
════════════════════════
ⴵ Time: Fri, 05 Jun 2026 05:58:28 GMT
════════════════════════
⌗ Tags: #cicd #application_security #github_actions #shift_left_security #devsecops
Medium
Building a Parallel Security Gate in CI: Combining Secret Scanning, Dependency Audits, and SAST…
One of the biggest challenges in DevSecOps isn’t convincing teams that security matters.
❤1
⤷ Title: Poisoned Pipeline in Google’s Gemini-CLI: workflow_run PPE
════════════════════════
𐀪 Author: Rajat shukla
════════════════════════
ⴵ Time: Sat, 20 Jun 2026 16:55:15 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #github_actions #google #supply_chain_security
════════════════════════
𐀪 Author: Rajat shukla
════════════════════════
ⴵ Time: Sat, 20 Jun 2026 16:55:15 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #github_actions #google #supply_chain_security
Medium
Poisoned Pipeline in Google’s Gemini-CLI: workflow_run PPE
How attacker-controlled artifact data flows into a privileged GitHub Actions context and exposes GEMINI_API_KEY — found via Google OSS VRP.
⤷ Title: Gemini CLI Vulnerability Hits Maximum CVSS 10 Score
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 29 Jun 2026 01:16:58 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_12537 #Gemini CLI #GitHub Actions #Vulnerability
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 29 Jun 2026 01:16:58 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_12537 #Gemini CLI #GitHub Actions #Vulnerability
Daily CyberSecurity
Gemini CLI Vulnerability Hits Maximum CVSS 10 Score
A critical Gemini CLI vulnerability (CVE-2026-12537) exposes developer workflows to maximum severity attacks. Google disclosed this CVSS 10 rating flaw recently. TL;DR A critical Gemini CLI vulner…
⤷ Title: GitLost: GitHub’s AI Agent Tricked Into Leaking Private Repository Data
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 13:00:20 +0000
════════════════════════
⌗ Tags: #Security #Agentic AI #Cybersecurity #GitHub #GitHub Actions #GitLost #Privacy #Repository #Vulnerability
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 13:00:20 +0000
════════════════════════
⌗ Tags: #Security #Agentic AI #Cybersecurity #GitHub #GitHub Actions #GitLost #Privacy #Repository #Vulnerability
Hackread
GitLost: GitHub’s AI Agent Tricked Into Leaking Private Repository Data
Noma Labs details GitLost, a prompt injection flaw that made GitHub's AI agent expose private repo data through a crafted public issue and guardrail failures.