🏷️Topic

Supply_chain_attack

3 articles
First tracked: Apr 3, 2026
Last updated: Jun 21, 2026

Latest Coverage

Google says hackers stole data from 200 companies following Gainsight breach

↗

Google confirms data from 200+ Salesforce instances was accessed via a Gainsight breach, tied to the Scattered Lapsus$ Hunters, with multiple affected vendors and ongoing investigations.

Nov 23, 20251%

Incident Report: CVE-2024-YIKES

↗

A multi-stage supply-chain attack cascaded through npm → Rust → Python tooling, compromising millions and triggering a formal CVE with ongoing regulatory classification debates.

May 10, 20261%

Post Mortem: axios NPM supply chain compromise

↗

Two malicious Axios releases were briefly published on npm due to a compromised maintainer account, introducing a remote-access trojan via plain-crypto-js; remediation focuses on OIDC-based publishing, immutable releases, CI publishing, and credential hygiene.

Apr 3, 20261%

Related Entities

👤PersonOpenjs Security Working Group
1
🏷️TopicNpm
14
🏷️TopicSecurity_post_mortem
1
📈StockOIDC
4
🏷️TopicAxios
19