Supply-Chain

untitled design (1)

MixShell Malware Uses Contact Forms to Target U.S. Supply Chain Manufacturers

Cybersecurity experts have uncovered a highly sophisticated social engineering campaign that is deploying MixShell, a stealthy in-memory malware, against key manufacturing companies vital to the global supply chain. This malicious operation, tracked by Check Point Research under the name ZipLine, takes an unusual approach to infiltration. A Shift from Traditional Phishing Instead of relying on […]

MixShell Malware Uses Contact Forms to Target U.S. Supply Chain Manufacturers Read More »

add a heading (1)

Supply Chain: Malicious PyPI, npm Packages Exploit Dependencies

Malicious Python and npm Packages Uncovered in Supply Chain Attacks Cybersecurity researchers have uncovered a malicious package on the Python Package Index (PyPI) that introduced harmful behavior through a hidden dependency, enabling persistence and remote code execution. The package, named termncolor, achieved its malicious activity via a dependency called colorinal, as detailed by Zscaler ThreatLabz.

Supply Chain: Malicious PyPI, npm Packages Exploit Dependencies Read More »