It has been a busy week for supply-chain attacks targeting open source software available in ... This was the third supply-chain attack Socket has observed on npm in the past week.
BigONE became the victim of a supply chain attack, which resulted in damages amounting to more than $27m losses. The attacker was able to withdraw funds from a network exploit. On July 16, the crypto exchange suffered a third-party attack ....
Dark Web-Powered SupplyChain Attacks ... Dark Web-Powered Supply Chain Attacks Key Findings from the 2025 RiskRadarReport ... sector breaches, driving up the value and frequency of supply chain attacks.
Supply chain attacks aim to infiltrate large targets indirectly by compromising third parties such as software developers, hardware suppliers, or service providers ... Galov emphasized that supply chain attacks often begin with smaller subcontractors.
Supply chain attacks in crypto exploit trusted dependencies, emerging as a major threat to crypto projects, which now have to stay vigilant on such threats ... .
The infections are the result of a supply-chain attack that compromised at least three software providers with malware that remained dormant for six years and became active only in the last few weeks.