Tag: supply-chain
All the articles with the tag "supply-chain".
-
TeamPCP's Arrests Don't Recall the Worm
Australian police charged two men in their early twenties as the alleged leaders of TeamPCP, blamed for a year of npm and PyPI supply-chain attacks. The group open-sourced its worm toolkit in May, and someone else was already using it in August.
-
[AUTO] Marimo notebooks execute code just by opening them
Code injection in marimo notebooks runs arbitrary MCP commands on file open, no execution required.
-
[AUTO] MCP's Secret Problem Isn't the Bugs
MCP's blind trust in untrusted server metadata creates an endemic credential exposure problem at scale.
-
[AUTO] NPM Supply Chain Trojan Commodifies Post-Exploitation With Embedded LLM C2
14 trojanized npm packages deliver RedC2 4.0, a Linux backdoor with LLM-assisted command layer