SUPPLY CHAIN
Supply Chain Attacks ArticlesArticles Attaques Supply Chain
Typosquatting, package hijacking, compromised maintainers: every major supply chain incident and how to defend.
Typosquatting, détournement de packages, mainteneurs compromis : chaque incident majeur et comment se défendre.
Results for Résultats pour
No articles matched your search
Aucun article ne correspond à votre recherche
Phantom Gyp Wave 2 in 2026: Miasma npm Worm Hits @vapi-ai/server-sdk, ai-sdk-ollama & 57 Packages
Phantom Gyp Vague 2 en 2026 : Ver npm Miasma sur @vapi-ai/server-sdk, ai-sdk-ollama & 57 Packages
June 3, 2026 : 57 npm packages compromised in <60 minutes via binding.gyp — @vapi-ai/server-sdk (408K downloads/month) hit first, then ai-sdk-ollama (120K) & 55 more. The worm propagated through developer workstations (not CI/CD), backdoored AI coding assistants (.claude, .cursor, .gemini configs), and installs a dead-man’s switch that wipes your home directory if you revoke the stolen token. Detection & remediation guide.
3 juin 2026 : 57 packages npm compromis en <60 min via binding.gyp — @vapi-ai/server-sdk (408K téléchargements/mois) touche en premier, puis ai-sdk-ollama (120K) & 55 autres. Le ver s’est propagé via les postes développeurs (pas le CI/CD), a backdooré les assistants IA (.claude, .cursor, .gemini) et installe un interrupteur homme-mort qui efface votre home si vous révoquez le token volé. Guide de détection & remédiation.
npm npmMiasma npm Supply Chain Attack in 2026: Red Hat @redhat-cloud-services, Phantom Gyp & SLSA Provenance Bypass
Attaque Supply Chain npm Miasma en 2026 : Red Hat @redhat-cloud-services, Phantom Gyp & Bypass Provenance SLSA
June 1, 2026: 32 @redhat-cloud-services npm packages backdoored via a compromised Red Hat employee GitHub account & GitHub Actions OIDC tokens. Phantom Gyp — a 157-byte binding.gyp — bypasses --ignore-scripts entirely. Credential-stealing worm with forged SLSA provenance harvests SSH keys, AWS/GCP/Azure credentials, Vault tokens & K8s secrets. Full remediation checklist.
1er juin 2026 : 32 packages npm @redhat-cloud-services backdoorés via un compte GitHub d’employé Red Hat compromis & des tokens OIDC GitHub Actions. Phantom Gyp — un binding.gyp de 157 octets — contourne complètement --ignore-scripts. Ver vol de credentials avec provenance SLSA forgée, ciblant clés SSH, credentials AWS/GCP/Azure, tokens Vault & secrets K8s. Checklist de remédiation complète.
Guides GuidesTerraform & IaC Security in 2026: CVE-2025-13357 (Vault Auth Bypass), tfstate Secrets & Checkov/Trivy Hardening Guide
Sécurité Terraform & IaC en 2026 : CVE-2025-13357 (Bypass Auth Vault), Secrets tfstate & Guide Durcissement Checkov/Trivy
CVE-2025-13357 (CVSS 7.4) in the Vault Terraform Provider sets deny_null_bind=false by default — attackers can authenticate to Vault without credentials. tfstate stores every secret in plaintext: sensitive=true only masks CLI output. Checkov vs Trivy vs tfsec comparison, OIDC CI/CD guide & OpenTofu native state encryption.
CVE-2025-13357 (CVSS 7.4) dans le Vault Terraform Provider définit deny_null_bind=false par défaut — les attaquants peuvent s’authentifier dans Vault sans credentials. tfstate stocke chaque secret en clair : sensitive=true ne masque que la sortie CLI. Comparaison Checkov vs Trivy vs tfsec, guide OIDC CI/CD & chiffrement natif OpenTofu.
Guides GuidesOWASP Top 10 for LLM Applications in 2026: Prompt Injection, Excessive Agency & Agentic AI Developer Guide
OWASP Top 10 pour Applications LLM en 2026 : Prompt Injection, Agence Excessive & Guide Développeur IA Agentique
73% of production AI deployments are vulnerable to prompt injection. CVE-2025-68664 (CVSS 9.3) chains LangChain serialization into secret extraction. OWASP released a dedicated Agentic Top 10 in December 2025. LLM01–LLM10 explained with real CVEs, attack patterns & hardening checklist for developers building LLM-powered apps.
73% des déploiements IA en production sont vulnérables à l’injection de prompt. CVE-2025-68664 (CVSS 9.3) chaîne la sérialisation LangChain en extraction de secrets. OWASP a publié un Top 10 Agentique dédié en décembre 2025. LLM01–LLM10 expliqués avec CVE réelles, patterns d’attaque & checklist de durcissement pour développeurs.
Guides GuidesGitHub Copilot Workspace & Agentic Code Security in 2026: CVE-2026-41109, IDEsaster & MCP Supply Chain Crisis
Sécurité GitHub Copilot Workspace & Code Agentique en 2026 : CVE-2026-41109, IDEsaster & Crise Supply Chain MCP
CVE-2026-41109 (CVSS 8.8) lets unauthenticated attackers inject malicious Copilot suggestions. IDEsaster found 30+ CVEs — 100% of AI IDEs vulnerable to data theft & RCE. MCP design flaw exposes 150M+ downloads to arbitrary command execution. AGENTS.md poisoning, RoguePilot repo takeover & full hardening guide.
CVE-2026-41109 (CVSS 8.8) permet à des attaquants non authentifiés d’injecter des suggestions Copilot malveillantes. IDEsaster : 30+ CVE — 100% des IDE IA vulnérables au vol de données & RCE. Le défaut MCP expose 150M+ téléchargements à l’exécution de commandes. Empoisonnement AGENTS.md, RoguePilot & guide de durcissement complet.
Guides GuidesGitHub Actions Security Hardening in 2026: Least-Privilege Permissions, SLSA Build Levels & the 2026 Roadmap
Durcissement Sécurité GitHub Actions en 2026 : Permissions Moindre Privilège, SLSA Build Levels & Roadmap 2026
76 of 77 trivy-action tags poisoned in March 2026, 23K+ repos compromised via tj-actions. Complete hardening guide: least-privilege GITHUB_TOKEN permissions, environment secrets, SHA pinning, SLSA Build Levels, reusable workflow risks & the scoped secrets + native egress firewall roadmap.
76 des 77 tags trivy-action empoisonnés en mars 2026, 23K+ dépôts compromis via tj-actions. Guide complet de durcissement : permissions GITHUB_TOKEN moindre privilège, secrets d’environnement, pinning SHA, SLSA Build Levels, risques workflows réutilisables & roadmap secrets portés + pare-feu de sortie natif.
Laravel LaravelLaravel-Lang Supply Chain Attack in 2026: 700 Versions Backdoored & Git Tag Rewrite Bypass
Attaque Supply Chain Laravel-Lang en 2026 : 700 Versions Backdoorées & Git Tag Rewrite Bypass
May 22, 2026: attackers rewrote 700+ git tags across 4 Composer packages in under 90 minutes, deploying a 5,900-line PHP credential stealer to 10.3M+ installs. AWS keys, GitHub tokens, crypto wallets, .env files — all targeted. Detection checklist & incident response guide.
22 mai 2026 : des attaquants ont réécrit 700+ tags git dans 4 packages Composer en moins de 90 minutes, déployant un credential stealer PHP de 5 900 lignes sur 10,3M+ installations. Clés AWS, tokens GitHub, wallets crypto, fichiers .env — tout ciblé. Guide de détection & réponse à l’incident.
Guides GuidesOWASP Dependency-Check vs Trivy vs Grype vs Snyk in 2026: Which Scanner Should You Use?
OWASP Dependency-Check vs Trivy vs Grype vs Snyk en 2026 : Quel Scanner Choisir ?
Practical 2026 comparison of the 4 most-used dependency scanners. Trivy 32K+ stars & 14s scans, Grype 96.2% CVE recall with EPSS scoring, OWASP DC false positive pitfalls via CPE/NVD, Snyk $126K/yr for 100 devs. Decision framework for DevSecOps teams.
Comparaison pratique 2026 des 4 scanners de dépendances les plus utilisés. Trivy 32K+ stars & scans 14s, Grype 96,2% recall CVE avec scoring EPSS, faux positifs OWASP DC via CPE/NVD, Snyk 126K$/an pour 100 devs. Arbre de décision pour équipes DevSecOps.
Guides GuidesGitHub Copilot & AI Code Assistants Security in 2026: RoguePilot, Slopsquatting & Prompt Injection Guide
Sécurité GitHub Copilot & Assistants IA en 2026 : RoguePilot, Slopsquatting & Guide Injection de Prompt
RoguePilot (Feb 2026) exfiltrates GITHUB_TOKEN via passive prompt injection through a crafted GitHub Issue — full repo takeover. Copilot Chat CVSS 9.6 leaked private source code. 19.7% of AI-suggested packages don’t exist (slopsquatting). 45% of AI-generated code fails OWASP Top 10. Complete hardening guide: token scoping, package verification, SAST gates & AI config file auditing.
RoguePilot (fév. 2026) exfiltre le GITHUB_TOKEN via une injection de prompt passive dans une Issue GitHub crafted — prise de contrôle complète du dépôt. Copilot Chat CVSS 9.6 a divulgué du code source privé. 19,7% des packages suggérés par l'IA n'existent pas (slopsquatting). 45% du code IA échoue à l'OWASP Top 10. Guide complet : portée tokens, vérification packages, portes SAST & audit fichiers config IA.
npm npmnpm package.json Security Best Practices in 2026: Lifecycle Scripts, Lockfile Integrity & Provenance Guide
Meilleures Pratiques de Sécurité package.json npm en 2026 : Scripts Lifecycle, Intégrité Lockfile & Guide Provenance
454,648 malicious npm packages in 2025. postinstall hooks compromised Axios (100M dl/week), Bitwarden CLI & TanStack in 2026. Complete guide: scripts hardening, lockfile integrity, overrides for transitive CVEs, private registry .npmrc config & provenance attestation — only 12% of top packages ship with it.
454 648 packages npm malveillants en 2025. Les hooks postinstall ont compromis Axios (100M dl/sem), Bitwarden CLI & TanStack en 2026. Guide complet : durcissement des scripts, intégrité lockfile, overrides pour CVE transitives, config .npmrc registre privé & attestations de provenance — seulement 12% des top packages les embarquent.
Guides GuidesGitHub Dependabot Security Alerts in 2026: AI Fixes, Malware Detection & How to Stop Alert Fatigue
Alertes Sécurité Dependabot en 2026 : Correctifs IA, Détection Malware & Comment Arrêter la Fatigue des Alertes
Dependabot gained malware detection for npm (March 2026) and AI agent fix assignment — Copilot, Claude & Codex (April 2026). Yet 85% of security PRs go unmerged. Complete 2026 guide: auto-triage rules with EPSS, GHSA vs CVE gap (213K unreviewed advisories), dependabot.yml best practices & what Dependabot still misses.
Dependabot a ajouté la détection de malware npm (mars 2026) et l'assignation d'agents IA — Copilot, Claude & Codex (avril 2026). Pourtant 85% des PRs sécurité ne sont pas fus iquées. Guide complet 2026 : règles d'auto-triage avec EPSS, fossé GHSA vs CVE (213K advisories non examinés), meilleures pratiques dependabot.yml & ce que Dependabot manque encore.
Supply Chain Supply ChainMalicious VS Code Extensions in 2026: GlassWorm, MaliciousCorgi & Developer Supply Chain Security Guide
Extensions VS Code Malveillantes en 2026 : GlassWorm, MaliciousCorgi & Guide Sécurité Supply Chain
GlassWorm planted 73 malicious extensions on OpenVSX (April 27, 2026) — the 4th wave since October 2025. MaliciousCorgi silently exfiltrated source code from 1.5M developer machines via AI-branded extensions. CVE-2025-65717 (CVSS 9.1) in Live Server (72M installs) remains unpatched. Complete audit checklist, CVE breakdown & enterprise hardening guide.
GlassWorm a planté 73 extensions malveillantes sur OpenVSX (27 avril 2026) — la 4e vague depuis octobre 2025. MaliciousCorgi a silencieusement exfiltré du code source depuis 1,5M de machines de développeurs via des extensions IA. CVE-2025-65717 (CVSS 9.1) dans Live Server (72M installations) reste non corrigée. Check-list d’audit complète, analyse CVE & guide de durcissement entreprise.
Monitor your dependencies automatically
Surveillez vos dépendances automatiquement
Upload your lockfiles and get instant CVE alerts. No code access required.
Uploadez vos lockfiles et recevez des alertes CVE instantanées. Aucun accès au code requis.
Start your 14-day free trial Demarrer l'essai gratuit 14 jours