Scroll down for the latest supply chain security news & articles from Infosecurity Magazine
Subscribe to our weekly newsletter for the latest in industry news, expert insights, dedicated information security content and online events.
Threat actors hijacked the popular npm package axios to spread RAT malware after compromising an open‑source maintainer’s account, researchers warn
TeamPCP is exploring ways to monetize the secrets harvested during supply chain attacks, with identified ties to the Lapsus$ and Vect ransomware gangs
Tax-season phishing floods deliver RMM malware, credential theft, BEC and tax-form scams
Python package LiteLLM compromised with credential-stealing malware linked to TeamPCP threat group
The Vidar 2.0 infostealers is deployed through fake free game cheats on GitHub and Reddit
Android’s LSPosed-based attack hijacks payment apps via runtime manipulation and SIM-binding bypass