Index live· 1,284 files · 148 editions
ForensicPost

Search the index

5 results
Try
Results for “Supply chain compromise”Newest first
26-0717
File

AsyncAPI npm Compromise Ran Its Payload at Import, Not Install

Execution moved from install to import. The flag everyone added after the last campaign is still set, and no longer covers anything.

UnattributedImport-time payloadCloudSupply chain
Sev 4TargetAsyncAPI npm packagesActorUnattributed
26-0606
File

A Worm in the Registry, Wearing a Vendor’s Name

A credential-stealing worm in a major vendor’s npm namespace. The namespace is the trust signal, and it delivered the reviewer’s assumption too.

UnattributedPackage compromiseCloudSupply chain
Sev 4TargetRed Hat-associated npm packagesActorUnattributed
26-0408
File

Enterprise Packages, Consumer Registry, No Separation

The most heavily governed system in the organisation, with a dependency path that has no governance attached to it.

UnattributedPackage compromiseCloudSupply chain
Sev 3TargetSAP-related npm packagesActorUnattributed
23-0420
File

Mandiant Traced the 3CX Compromise to a Trojanised X_TRADER Installer

Nobody assessing a phone-system vendor thinks to ask about its staff’s trading software.

UNC4736Trojanised X_TRADER installerTechnologySupply chain
Sev 5Target3CXActorUNC4736USA
23-0329
File

Mandiant Says One Supply Chain Compromise Caused Another at 3CX

Code signing answers "did this come from the vendor". Here the answer was yes, and it was the wrong question.

UNC4736Supply chain compromiseTechnologySupply chain
Sev 5Target3CXActorUNC4736
© 2026 ForensicPost Media · the desk · newsletterGlossaryNo search logging