
.avif)
Software Supply Chain Security News
Stay up to date with the latest software supply chain security incidents, including malicious packages, dependency attacks, and real-world breaches. We break down what happened, why it matters, and what developers should fix to stay ahead.

Shai-Hulud Rises From the Dead after 111 days
A known Shai-Hulud worm payload sat dormant for 111 days, then republished to npm, right past the malware scanning meant to catch it.
Novel supplychain.local Go worm appears
"supplychain.local": malicious code found in MemTensor's npm plugin (0.1.21, 0.1.23) and PyPI's MemoryOS (2.0.34).
Graphalgo campaign spreads to Terraform providers and Go Modules
Aikido found Graphalgo-linked Go malware in Terraform providers and Go Modules, using targeted triggers, Slack, and blockchain C2.
Compromised Flutter package on pub.dev contains XCSSET malware
We detected XCSSET malware inside a compromised Flutter package on pub.dev. Here is a full breakdown of the infection chain, propagation modules, and stealer logic we found inside.
Shai-Hulud Rises From the Dead after 111 days
A known Shai-Hulud worm payload sat dormant for 111 days, then republished to npm, right past the malware scanning meant to catch it.
StyleSmuggler fix: patch the Magento and Adobe Commerce RCE
StyleSmuggler is an unauthenticated RCE hitting Magento and Adobe Commerce, with no CVE and no Adobe patch yet. Aikido already has the fix.
MECCHA CHAMELEON can't hide from the RCE
We found a second delayed RCE in MECCHA CHAMELEON: a malicious custom map could write files anywhere on your system and run code after a restart. Now patched in 4.0.0.
Popular code generator for TanStack Query hit by supply chain worm
A supply chain worm was found hiding in @7nohe/openapi-react-query-codegen, a popular code generator for TanStack Query, stealing credentials and spreading itself to every package the victim maintains.
Popular Rust crates arrayref, append-only-vec, and internment compromised in Supply Chain Attack
A supply chain attack compromised popular Rust crates, arrayref, append-only-vec, and internment, injecting a dependency on the malicious proc-macro1 package that downloads and executes a remote payload at build time.
Yet another RCE in Gogs, but it's fixed this time!
CVE-2026-52813 | An Aikido pentesting agent flagged a path traversal in Gogs. We escalated it to full RCE and reported two more bugs, all fixed in 0.14.3.
Keyv and friends compromised in active Shai-Hulud supply chain attack
Mini Shai-Hulud malware was injected into keyv and eight related npm packages on August 4, 2026 after an attacker compromised the maintainer's GitHub account
Get secure now
Secure your code, cloud, and runtime in one central system.
Find and fix vulnerabilities fast automatically.



