Ci-Cd
MemTensor MemOS Packages Backdoored with sckit, a Go Credential-Stealing Worm, on npm and PyPI
Malicious releases of MemTensor's MemOS OpenClaw plugin (npm) and MemoryOS (PyPI) deliver sckit, a cross-platform Go implant that steals 13 credential types and carries worm templates for npm, PyPI and GitHub Actions.
Plugin4Shell: SHA-Pinning Bypass Enables Zero-Click RCE Across Claude Code, Codex, Copilot, and Gemini CLI
A Git reference-resolution flaw dubbed Plugin4Shell lets a plugin repository owner silently swap the code behind a SHA-pinned install across all four major AI coding agents, achieving zero-click RCE on developer and CI machines that trust the pin.
Mini Shai-Hulud "Trinitite": TanStack Codegen Tool Poisoned via Hijacked GitHub OIDC Release Workflow
A new Mini Shai-Hulud wave dubbed Trinitite compromised @7nohe/openapi-react-query-codegen, a 150K-download-a-week TanStack code generator, by hijacking its GitHub Actions OIDC publish workflow rather than stealing a token.
Supply Chain Security Vendor RapidFort Allegedly Breached in CanisterWorm Fallout — 569GB of Customer Pipeline Data Listed for Sale
A threat actor claims to be selling 569GB of RapidFort's internal pipeline data — including customer cross-account IAM templates, kubeconfigs, and plaintext AWS credentials — allegedly extracted during the March 2026 CanisterWorm/TeamPCP campaign.
Jenkins CVE-2026-70426: Remoting Deserialization Filter Bypass Enables Controller RCE
CVE-2026-70426 (CVSS 9.0) lets an attacker with agent-level access bypass Jenkins' JEP-200 class filter via a fallback path in Remoting, achieving code execution on the controller. Patch to 2.576 / LTS 2.568.2 now.
Keyv npm Worm Hits 800+ Packages, Pulls C2 From an Ethereum Smart Contract
A compromised [email protected] release triggered a self-propagating npm worm that poisoned 800+ packages in hours, planting Claude Code and VS Code persistence hooks and fetching C2 addresses via live Ethereum smart-contract calls.
SleeperGem: Hijacked Dormant RubyGems Accounts Drop a Persistent Backdoor on Developer Machines
Researchers disclose SleeperGem, a RubyGems supply-chain attack that hijacked long-dormant maintainer accounts to publish trojanized gems whose loader specifically targets developer workstations while evading CI runners.
AsyncAPI npm Packages Backdoored via GitHub Actions 'Pwn Request', Deliver Miasma RAT
A stolen CI token let attackers push a malicious commit into AsyncAPI's npm packages on July 14, delivering an IPFS-hosted Miasma RAT to millions of weekly installs — this time configured as a stealthy botnet, not a self-propagating worm.
Jscrambler npm Package Compromised: Rust Infostealer Shipped via Preinstall Hook
The official jscrambler npm package was compromised to publish version 8.14.0 with a preinstall hook that drops a cross-platform Rust infostealer targeting cloud credentials, crypto wallets, and password managers.
17 Malicious npm/PyPI Packages Impersonate Paysafe, Skrill, and Neteller SDKs to Steal CI/CD Secrets
A coordinated typosquatting campaign published 13 npm and 4 PyPI packages that mimic Paysafe, Skrill, and Neteller payment SDKs, returning fake success responses while exfiltrating API keys, AWS credentials, and CI tokens to an obfuscated C2 host.
GuardFall: Decades-Old Bash Quoting Tricks Defeat Safety Guards in 10 of 11 Open-Source AI Coding Agents
Adversa AI's GuardFall research shows that quote removal, $IFS spacing, command substitution, and other decades-old shell tricks bypass the command guards in opencode, Goose, Cline, Aider, and seven other open-source AI coding agents — turning a poisoned README into silent credential theft.
Jenkins CVE-2026-53435: config.xml Deserialization RCE Exploited Five Days After Disclosure
CVE-2026-53435 (CVSS 9.0) is an unsafe-deserialization RCE in Jenkins' config.xml handling. Disclosed June 10, a public PoC is now driving in-the-wild exploitation against internet-exposed CI/CD servers. Patch to weekly 2.568 or LTS 2.555.3.
Proto6: Six protobuf.js Flaws Turn Trusted Schemas Into RCE and DoS Across gRPC, Cloud, and AI Stacks
Cyera's Proto6 research discloses six CVEs in protobuf.js, including a prototype-pollution-to-RCE chain, in a library pulled 50M+ times a week across gRPC, Google Cloud SDKs, vector databases, and CI/CD.
Claude Code's GitHub Action: One Malicious Issue Could Hijack Any Public Repo
A permission bypass chained with prompt injection in Anthropic's Claude Code GitHub Action let a single crafted issue make the agent leak CI secrets and OIDC request tokens — a clean path to poisoning the action's own supply chain. Patched in v1.0.94.
Red Hat Cloud Services npm Packages Hijacked in 'Miasma' Shai-Hulud Worm
A Mini Shai-Hulud wave dubbed 'Miasma' poisoned ~30 @redhat-cloud-services npm packages on June 1 via a compromised CI/CD pipeline, dropping a Bun-based credential stealer with a destructive dead-man switch.
JINX-0164: Fake Recruiters, a macOS RAT, and a Pivot Into Code Distribution Pipelines
Wiz details JINX-0164, a financially motivated actor that uses LinkedIn recruiter lures to drop the AUDIOFIX macOS RAT, then moves from developer laptops into code distribution and CI/CD infrastructure.
Megalodon: 5,561 GitHub Repos Backdoored With Malicious CI/CD Workflows in Six Hours
An automated campaign tied to TeamPCP pushed 5,718 malicious commits to 5,561 GitHub repositories in a six-hour window, planting CI/CD workflows that exfiltrate cloud credentials and OIDC tokens at scale.
actions-cool/issues-helper Compromised: Every Tag Repointed to a Credential-Stealing Imposter Commit
An attacker repointed all 53 tags of the popular actions-cool/issues-helper GitHub Action to a single imposter commit that scrapes live CI/CD secrets out of runner process memory.
RubyGems Disables New Signups After Hundreds of Malicious Packages Target Registry Staff
RubyGems froze new account registration after an attacker uploaded hundreds of malicious gems on May 11-12 specifically targeting RubyGems engineers, with XSS payloads and credential-stealing exploits embedded in the packages.
Mini Shai-Hulud Wave 4: TanStack, Mistral AI, UiPath Hit by First-Ever SLSA-Attested Malicious npm Packages (CVE-2026-45321)
TeamPCP's fourth Mini Shai-Hulud wave compromised 42 TanStack packages, the Mistral AI SDK, UiPath, OpenSearch, and Guardrails AI by stealing OIDC tokens out of a GitHub Actions runner's process memory — and shipped malicious versions with valid SLSA Build Level 3 provenance attestations.