You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
-[Shai-hulud supply chain attack spreads token-stealing malware on npm](https://www.reversinglabs.com/blog/shai-hulud-worm-npm)
32
34
-[npm Chalk and Debug Packages Hit in Software Supply Chain Attack](https://www.sonatype.com/blog/npm-chalk-and-debug-packages-hit-in-software-supply-chain-attack)
33
-
-[Another npm Supply Chain Attack: The 'is' Package Compromise](https://www.stepsecurity.io/blog/another-npm-supply-chain-attack-the-is-package-compromise)
35
+
-[Another npm Supply Chain Attack: The 'is' Package Compromise](https://www.stepsecurity.io/blog/another-npm-supply-chain-attack-the-is-package-compromise)
Copy file name to clipboardExpand all lines: community/catalog/compromises/2025/nx-platform.md
+3-1Lines changed: 3 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,3 +1,5 @@
1
+
<!-- cSpell:ignore ngularity exfiltrated -->
2
+
1
3
# The Nx s1ngularity Attack Leading to Credentials Leak
2
4
3
5
On August 26, 2025, attackers released malicious versions of the nx and @nx/*
@@ -30,4 +32,4 @@ compromise.
30
32
31
33
-[Serious NX build compromise - what you need to know about the s1ngularity attack](https://www.kaspersky.com/blog/nx-build-s1ngularity-supply-chain-attack/54223/)
32
34
-[The Nx "s1ngularity" Attack: Inside the Credential Leak](https://blog.gitguardian.com/the-nx-s1ngularity-attack-inside-the-credential-leak/)
Copy file name to clipboardExpand all lines: community/catalog/compromises/2025/oracle-cloud.md
+3-1Lines changed: 3 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,3 +1,5 @@
1
+
<!-- cSpell:ignore Exfiltrated exfiltrated -->
2
+
1
3
# Oracle Cloud SSO and Identity Infrastructure Compromise
2
4
3
5
The Oracle Cloud data breach, publicly disclosed around March 21, 2025, involved
@@ -39,4 +41,4 @@ critical part of its service publishing and access layer.
39
41
40
42
-[CloudSEK – The Biggest Supply Chain Hack of 2025: 6M Records Exfiltrated from Oracle Cloud](https://www.cloudsek.com/blog/the-biggest-supply-chain-hack-of-2025-6m-records-for-sale-exfiltrated-from-oracle-cloud-affecting-over-140k-tenants)
-[Oracle Cloud Breaches Lead to CISA Guidance and Lawsuits](https://www.americanbar.org/groups/health_law/news/2025/4/oracle-cloud-breaches-lead-to-cisa-guidance-lawsuits/)
44
+
-[Oracle Cloud Breaches Lead to CISA Guidance and Lawsuits](https://www.americanbar.org/groups/health_law/news/2025/4/oracle-cloud-breaches-lead-to-cisa-guidance-lawsuits/)
Copy file name to clipboardExpand all lines: community/catalog/compromises/README.md
+5-5Lines changed: 5 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -8,7 +8,7 @@ The goal is not to catalog every known supply chain attack, but rather to captur
8
8
many examples of different kinds of attack, so that we can better understand the
9
9
patterns and develop best practices and tools.
10
10
11
-
For definitions of each compromise type, please check out our [compromise definitions page](community/catalog/compromises/compromise-definitions.md)
11
+
For definitions of each compromise type, please check out our [compromise definitions page](compromise-definitions.md)
12
12
13
13
We welcome additions to this catalog by [filing an
14
14
issue](https://github.com/cncf/tag-security/issues/new/choose) or [github pull
@@ -74,7 +74,7 @@ of compromise needs added, please include that as well.
74
74
|[NPM reverse shells and data mining](2020/nodejs.md)| 2020 | Dev Tooling |[1](https://www.bleepingcomputer.com/news/security/npm-nukes-nodejs-malware-opening-windows-linux-reverse-shells/)|
75
75
|[Binaries of the CLI for `monero` compromised](2019/monero.md)| 2019 | Publishing Infrastructure |[1](https://web.getmonero.org/2019/11/19/warning-compromised-binaries.html), [2](https://github.com/monero-project/monero/issues/6151), [3](https://web.archive.org/web/20230630012925/https://old.reddit.com/r/Monero/comments/dyfozs/security_warning_cli_binaries_available_on/)|
76
76
|[Webmin backdoor](2019/webmin-backdoor.md)| 2019 | Dev Tooling |[1](https://www.zdnet.com/article/backdoor-found-in-webmin-a-popular-web-based-utility-for-managing-unix-servers/), [2](http://www.webmin.com/exploit.html)|
77
-
|[purescript-npm](2019/purescript-npm.md)| 2019 | Source Code |[1](https://www.npmjs.com/advisories/1082) and [2](https://www.npmjs.com/advisories/1082)|
|[Debian infra compromise](2003/debian.md)| 2003 | Publishing infrastructure |[1](https://www.debian.org/News/2003/20031202)|
121
121
|[Unix Support Group login backdoor](1975/login-bell.md)| 1975 | Dev Tooling |[1](https://niconiconi.neocities.org/posts/ken-thompson-really-did-launch-his-trusting-trust-trojan-attack-in-real-life/)|
0 commit comments