Every watch, in order.
65 watches published so far. Each one captures what crossed the wire that day — new disclosures, fresh CISA KEV adds, package-hijack campaigns in progress — ranked by severity.
Supply Chain Watch · 2026-07-26 · A Quiet Sunday, Except for Dependabot's New Cooldown Window
The only story of the day was a defensive one — GitHub and PyPI shipped a built-in cooldown window for Dependabot, and nothing else moved.
Supply Chain Watch · 2026-07-25 · Budibase, Poweradmin, and blaze Batch the Day, Then a Predictable-Key Critical Lands Late
The day's shape is the partial fix — GitPython and Pheditor both got hit again by the same bug class a prior patch was supposed to have closed, while six other platforms dropped chained multi-CVE batches in a single shot.
Supply Chain Watch · 2026-07-24 · Budibase, OpenAM/OpenDJ, and a Late Shescape Escape-Bypass Critical
A fourth critical landed after First Watch — npm shell-escaping library Shescape ships its own shell-injection bypass on Windows CMD — capping a day that already saw seven criticals across Budibase and OpenAM/OpenDJ.
Supply Chain Watch · 2026-07-23 · Two Auth.js Criticals, A Quiet Batch Behind Them
Two Auth.js advisories that can silently disable authentication anchor a day otherwise dominated by open redirects and memory-exhaustion bugs — React Router's four-advisory redirect-hardening batch, a paired pypdf infinite-loop fix, and a fresh PHPSpreadsheet SSRF bypass — with nothing yet confirmed under active attack.
Supply Chain Watch · 2026-07-22 · A four-wave Wednesday — Gitea, n8n twice, Netty, Next.js, Jetty, JupyterLab, LiteLLM — plus two KEV criticals
Late escalation at 21:00 ET: a fourth disclosure wave — 50 more advisories spanning a second n8n batch plus first-time appearances from Next.js, Eclipse Jetty, JupyterLab, and LiteLLM — landed within 75 minutes of the day's 18:00 synthesis, pushing the day's total past 135 items and its high-severity count past 55.
Supply Chain Watch · 2026-07-21 · A 21-advisory Gitea disclosure lands on a KEV-heavy day
A single coordinated disclosure dropped 21 Gitea advisories in about two hours — four critical, including a Docker image default that hands any network attacker admin — on top of a KEV day already carrying a live WordPress SQLi-to-RCE chain.
Supply Chain Watch · 2026-07-20 · A 90-advisory GHSA wave overshadows SleeperGem's RubyGems hijack
A same-day GHSA wave that ran from 6pm to past 9pm ET eventually reached 90 advisories, overshadowing SleeperGem's quiet RubyGems hijack — headlined by a critical node-tar bug reachable through every npm install, a Composer bug that lets a malicious transitive dependency write files outside vendor/, and a second, equally large round of Pillow, Axios, and .NET disclosures that landed after First Watch had already gone to print.
Supply Chain Watch · 2026-07-19 · SleeperGem's dormant-account hijack on RubyGems, on an otherwise quiet Sunday
SleeperGem's dormant-maintainer-account hijack on RubyGems was the day's lone confirmed supply-chain hit, on an otherwise quiet Sunday.
Supply Chain Watch · 2026-07-18 · A quiet Saturday, one escalation
The only development on an otherwise silent Saturday was ACR Stealer's ClickFix campaign graduating from a researcher writeup to a vendor-confirmed, enterprise-scale surge.
Supply Chain Watch · 2026-07-17 · ViteVenom and the sibling-path pattern
A blockchain-controlled npm campaign returns as ViteVenom, while five unrelated projects each shipped a patch that admitted its first fix missed the vulnerability's sibling path.
Supply Chain Watch · 2026-07-16 — Trojanized installers, a self-propagating npm worm, and two same-day KEV adds
A trojanized-installer campaign, a self-propagating npm worm, and two same-day CISA KEV adds converged today — each one weaponizing a channel defenders trust by default.
Supply Chain Watch · 2026-07-15 — A late Datadog six-language tracer DoS and a ViewComponent XSS bypass push the day past 30 highs
MantisBT's zero-password admin takeover held the day's top story, but a 9pm wave of 22 GHSA advisories — a six-language Datadog tracer DoS, a Rails ViewComponent XSS bypass, and a django-haystack eval() RCE — pushed the day's high-severity count past 30.
Supply Chain Watch · 2026-07-14
A pile-up day: four new FacturaScripts advisories, three same-root-cause Anyquery RCE-class bugs, and three separate MCP-server disclosures landed alongside two live GitHub/npm impersonation campaigns and four newly-confirmed CISA KEV exploits.
Supply Chain Watch · 2026-07-13 — A late Kimai Docker-secret account takeover and a brute-forceable FacturaScripts 2FA bypass escalate the day to five criticals
A late 21:00 ET wave adds two more confirmed-exploitable criticals — a hardcoded Docker default secret enabling Kimai account takeover and a brute-forceable FacturaScripts 2FA bypass — on top of a day that already carried a newly-exploited legacy Cisco IOS bug, DIRAC's double eval()-to-RCE disclosure, and day three of the unresolved jscrambler npm infostealer.
Supply Chain Watch · 2026-07-12 — An all-quiet edition, with yesterday's jscrambler MCP-credential infostealer still the only live thread
A rare all-quiet stretch: three straight passes today turned up nothing new, leaving yesterday's jscrambler MCP-credential infostealer as the only thread still worth chasing.
Supply Chain Watch · 2026-07-11 — A compromised jscrambler npm release ships a Rust infostealer that specifically hunts Claude Desktop, Cursor, and other MCP configs
A compromised jscrambler npm release spent three hours mutating past its own install-hook detection while its Rust infostealer went straight for Claude Desktop, Cursor, and other MCP server credentials.
Supply Chain Watch · 2026-07-10 — SiYuan answers YesWiki's 13-advisory morning with 7 of its own, three RCE chains deep, while a compromised Injective Labs repo ships a wallet-stealing npm package
A second coordinated multi-CVE batch — seven SiYuan advisories with three independent RCE chains — landed hours after this morning's YesWiki disclosure, while a compromised Injective Labs GitHub repo pushed a wallet-draining npm package into the wild.
Supply Chain Watch · 2026-07-09 — Wallet and payment SDKs hit across three ecosystems, YesWiki takes a 13-advisory teardown, then a late Elixir HTTP-client batch lands after bed-check
Late escalation at 21:00 ET: a fresh GHSA batch lands three more high-severity disclosures — header-leak and memory-exhaustion bugs across Elixir's two workhorse HTTP clients, Tesla and Mint — on top of a day already shaped by a three-ecosystem wallet/payment-credential wave and a 13-advisory YesWiki teardown.
Supply Chain Watch · 2026-07-08 — Agentic tooling's authless-API problem
Five unrelated AI-agent and MCP-adjacent tools — Langflow, Open WebUI, ha-mcp, ckan-mcp-server, and Serena — disclosed authorization or authentication gaps on the same day, the clearest sign yet that agentic tooling is shipping with the auth debt web frameworks paid off a decade ago.
Supply Chain Watch · 2026-07-06 — Late Escalation: Zcash Circuit Bug Caps a Nine-Advisory Day
Zebra disclosed a CVSS-9.3 soundness bug in Zcash's Orchard shielded-pool circuit at 21:00 ET, a late critical escalation onto a day that had already produced four separate critical dev-and-agent-tooling disclosures.
Supply Chain Watch · 2026-07-05 — A Quiet Day, Start to Finish
Nothing broke: no new CISA KEV entries, no GHSA advisories in scope, and no active-campaign writeups from Socket, Phylum, Hacker News, BleepingComputer, or Aikido across all three passes today.
PolinRider Keeps Scaling, and Little Else Broke
The DPRK-linked PolinRider campaign is now up to 108 malicious packages and browser extensions across four ecosystems, and it's the only story of the day — KEV, GHSA, and the rest of the RSS feeds stayed quiet.
Six Projects, One Coordinated-Disclosure Day
Six unrelated open-source projects each shipped a coordinated multi-CVE batch today, from Steeltoe's seven advisories to Zebra's twelve, while the MCP-gateway trust-boundary bug count for the week climbed to four.
Six MCP/agent-gateway projects disclose auth bugs in a day, Mautic and LaunchServer land unauth RCE-adjacent criticals
Six unrelated MCP and agent-gateway projects disclosed authorization or credential-handling bugs in the same 24 hours, making the agent-tooling trust boundary — not any single campaign — today's story.
PolinRider spreads to a fourth ecosystem, Rancher/SurrealDB/Sigstore dump mass disclosures, then two late MCP/DB credential-leak bugs land before bed
A North Korea-linked campaign expanded to a fourth ecosystem and Rancher, SurrealDB, and Sigstore all dropped mass-disclosure batches — then, in the final hour before bed, two more high-severity credential-leak bugs landed in an Apify MCP server and a Postgres SCRAM client.
Registry to trust root: a PyPI backdoor, a Fission node-escape pileup, and an SSRF in Sigstore's CA
A live PyPI backdoor campaign, a coordinated node-escape pileup in Fission's serverless platform, and an SSRF in Sigstore's signing CA hit every layer from registry to trust root on the same day.
Supply Chain Watch · 2026-06-29 — Stealers ride the trusted channels; SimpleHelp hits the KEV
Infostealers keep arriving through trusted channels — hijacked npm/Go packages, a KEV-listed SimpleHelp auth bypass, and a late wave of clipboard-stealing browser extensions — while OpenAM and Dgraph patch server-side identity and injection flaws.
Supply Chain Watch · 2026-06-28 — A quiet registry day exposes the AI coding agent's config as the new injection point
A quiet day on the registries threw the week's real shift into relief: both of today's disclosures weaponize the AI coding agent's auto-trusted setup surface — repo configs and MCP definitions — rather than any poisoned package.
Supply Chain Watch · 2026-06-27 — The worm reaches the credential brokers, and the day rhymes on one flaw
The Miasma worm crossed from npm into Backstage's GitLab and LDAP auth plugins, Polymarket lost roughly $3M to a poisoned frontend, and a wave of disclosures — Nezha, pnpm, Hackney, ex_aws_sns — all rhymed on one flaw: trusting attacker-controlled input as authorization.
Supply Chain Watch · 2026-06-26 — The worm spreads, the wheel rots, and pnpm becomes the attack surface
A self-replicating npm worm jumped to its third package set and a poisoned PyPI wheel harvested the same credentials by other means — then a late coordinated pnpm disclosure turned the package manager itself into the attack surface.
golang.org/x/crypto/ssh breaks open late on a Go-heavy day
A late coordinated disclosure cracks the golang.org/x/crypto/ssh stack open — a CVSS-10 public-key auth bypass and five more critical SSH/agent flaws — onto a day already defined by Shai-Hulud crossing into Go and OpenAM's five-way collapse.
OpenAM identity stack takes a third hit as three CVSS-10 RCEs open the day
Three CVSS-10 RCEs opened the day; a chainable pair of pre-auth OpenAM criticals closed it, making the identity stack the story two days running.
Supply Chain Watch · 2026-06-23 — Identity takes the brunt; late Snipe-IT tenancy batch
Identity infrastructure took the brunt — pre-auth RCE in OpenDJ, pre-auth XSS and LDAP injection in OpenAM, and LastPass breached through stolen OAuth tokens — while npm typosquats dropped a Windows RAT, CISA logged four exploited appliance flaws, and a late Snipe-IT disclosure batch added a cross-tenant data injection after the bell.
Supply Chain Watch · 2026-06-22 · The trusted update channel was the attack
The trusted update channel was the attack: ShapedPlugin shipped a CVSS-10 backdoor through official Pro-plugin releases for a month — and the evening brought a late wave of forge and npm-library disclosures, capped by a fresh SCIM prototype-pollution critical.
Supply Chain Watch · 2026-06-21 — A quiet Sunday on the registries
A quiet Sunday on the registries — no new criticals and no fresh KEV adds, leaving the day's only live thread an actively-exploited WordPress plugin leaking the API keys and OAuth tokens that downstream attacks usually have to phish for.
Supply Chain Watch · 2026-06-20 — A state actor claims the Mastra compromise
Microsoft pinned last week's 140-package Mastra AI npm compromise on North Korea's BlueNoroff while the agent stack kept failing in public — a third critical-class Langflow hole now on CISA KEV, fresh cross-tenant breaks in the agent-memory stores, and another MCP-server SSRF and path-traversal cluster.
Supply Chain Watch · 2026-06-19 — The agentic toolchain audits itself in public
The agentic toolchain audited itself in public all day — Langflow and Network-AI criticals, an MCP-server SSRF/XSS cluster, and cross-tenant breaks across the agent-memory stores — and kept going after dark with a LangSmith SDK file-read and a Lokka MCP Azure-token leak.
Supply Chain Watch · The agent ecosystem's bad day
AI agent frameworks and MCP servers became the day's soft target — a dozen-plus unauthenticated-control-plane and prompt-injection-to-RCE holes landed across PraisonAI, Crawl4AI, OpenClaw and the MCP tooling, while a real update-channel compromise hit WordPress and CISA flagged an actively-exploited Splunk file-write.
Supply Chain Watch · 2026-06-17 · The AI toolchain is the supply chain
The AI development toolchain became the supply chain: two live npm and IDE credential-theft campaigns landed alongside a flood of fresh advisories against the self-hosted LLM stack.
Supply Chain Watch · 2026-06-16 — AI-stack mass disclosure escalates after dark: Rclone unauth RCE, LiteLLM auth bypass, n8n CVSS-10 browser hole & cross-tenant cred takeover, Gitea/Gogs token-scope bypasses
The day escalated after dark: unauthenticated RCE in Rclone, an auth bypass in the LiteLLM proxy, a CVSS-10 unauthenticated browser-control hole and cross-tenant credential takeover in n8n, and a token-scope-bypass cluster across Gitea and Gogs piled onto the AI-development-stack mass disclosure and the IDE plugins caught stealing AI keys.
Supply Chain Watch · 2026-06-15 — Live WordPress CDN supply-chain attack, dev-tooling RCE, two KEV adds
A live CDN supply-chain attack on three widely-deployed WordPress plugins headlines a day of dev-tooling RCE and fresh CISA KEV adds.
A quiet registry day, and a decade-long auth-stack hijack
A rare quiet day across the registries, with the lone headline a decade-long hijack of a target's authentication stack that reframes identity as the supply chain's deepest dependency.
File Browser empties its disclosure queue
The week's File Browser disclosure run crests with six advisories dropped at once — unauth share leaks, a one-packet login DoS, zip-slip and symlink escapes — while esbuild's Deno installer quietly reopens a build-time RCE path.
Supply Chain Watch · 2026-06-12 — The AUR burns while the frameworks patch
Four hundred-plus Arch AUR packages are poisoned with an infostealer and eBPF rootkit on the same day Budibase, TYPO3 and File Browser ship coordinated emergency mass-patches.
Supply Chain Watch · 2026-06-11 — npm moves to disarm install scripts as a supply-chain worm's source leaks
npm moves to disarm install scripts on the same day a supply-chain worm's source code leaks and PDM lands its second code-execution flaw — the install-time attack surface is the whole story.
KEV deadline day, Miasma source leak, Claude Code Action MCP flaw — Supply Chain Watch 2026-06-10
CISA KEV deadlines for TanStack and Nx Console land today as Miasma's source code briefly leaks on GitHub and a new supply-chain vector — malicious MCP server config in pull requests — puts Claude Code Action CI pipelines at risk of secret exfiltration.
Self-propagating PyPI worms, five CISA KEVs, and a late Dex/PhoenixStorybook RCE wave
A late GHSA wave after 18:00 ET delivered unauthenticated RCE in PhoenixStorybook and a connector-ACL bypass in Dex, extending a day already shaped by the Shai-Hulud PyPI worm campaign and five CISA KEV additions.
Supply Chain Watch · Late KEV escalation — LiteLLM RCE caps a developer-toolchain day
A 21:00 ET KEV addition dropped a command-injection RCE in the open-source LiteLLM gateway onto the actively-exploited list — capping a day already shaped by two ransomware-linked developer-toolchain compromises, Nx Console and TanStack.
Supply Chain Watch · A quiet Sunday with one loud exception: Miasma's PyPI wave
The disclosure feeds went silent for the weekend, leaving one story standing: Miasma opened a Python propagation arm — 37 malicious PyPI wheels that execute on interpreter start, no import required.
Supply Chain Watch · Miasma reaches Microsoft's GitHub orgs, and DbGate hands over a CVSS 10
The Miasma worm crossed from npm into Microsoft's own GitHub estate — 73 repositories disabled across four organizations — while DbGate disclosed an unauthenticated CVSS-10 RCE.
Supply Chain Watch · A worm joins IronWorm on npm, and two KEV clocks run down
IronWorm's npm campaign doubles to 50-plus poisoned packages and picks up a self-spreading worm and a kernel rootkit, while CISA's KEV clock runs out on a Magento RCE tonight.
Supply Chain Watch · Two npm Worms and a Jupyter Cluster-Takeover
Two self-propagating npm worms hit the registry the same day a triple-critical SSTI flaw turns Jupyter's Kubernetes gateway into full cluster takeover.
Supply Chain Watch · 2026-06-03 — Developer-environment day: VS Code token steal, Jupyter K8s RCE trio, four KEV adds in 48 hours
A public VS Code / github.dev one-click token steal and a triple-critical RCE chain in Jupyter Enterprise Gateway land in the same 48-hour window CISA pushes four bugs to the KEV catalog and Wordfence logs hundreds of active hits on Kirki.
Two Vitest CVEs and a six-advisory praisonai cluster push developer tools into scope while CISA stacks three KEV adds
Two Vitest CVEs, six praisonai IDORs, and a conda write-anywhere push developer tooling into the day's attack surface while CISA stacks three KEV adds on top.
Supply Chain Watch · Mini Shai-Hulud worms into Red Hat's npm scope · 2026-06-01
Mini Shai-Hulud lands inside Red Hat's official npm scope — the trusted-vendor namespace compromise the ecosystem has been preparing for since last summer.
Famous Chollima moves to Packagist as KEV-backlog day winds down
DPRK's Contagious Interview crew ports its npm playbook to PHP, dropping malware in a Packagist-listed package on an otherwise quiet KEV-burndown Sunday.
Ghost CMS RCE backdoors 700+ dev sites with ClickFix; CISA hands PAN-OS a 72-hour clock; AI CLIs still trust the working directory
Developers are the day's target — a Ghost CMS RCE has backdoored 700+ tech and university sites into ClickFix droppers, CISA hands PAN-OS a 72-hour patch clock, and another AI-coding CLI ships with implicit working-directory trust.
Supply Chain Watch · 2026-05-29
Late escalation at 21:00 ET: a 19-advisory audit dump against PraisonAI lands on top of the morning's vm2/Redshift/Gotenberg trio — official A2A example reaches unauthenticated `eval()`, `deploy --type api` ships with auth disabled, and Platform's JWT key defaults to a hardcoded `dev-secret-change-me`.
Sicoob banking-SDK NuGet impersonator exfiltrates certs through Sentry; Symfony tops twenty advisories; paired Dulwich RCEs land late
A Sicoob banking-SDK impersonator on NuGet exfiltrates client certs through Sentry, the Symfony tranche tops twenty advisories, and a late-evening paired Dulwich disclosure revives the NTFS-hostile-tree-entry class on Windows.
CISA KEV-lists Nx Console + TanStack as the npm wave goes federal; Yamcs ships two mission-control RCEs
CISA closes the day with KEV adds for Nx Console and TanStack — turning the npm credential-stealing wave into a federal-mandate clock — while Yamcs hands aerospace operators two critical mission-control RCEs.
Late escalation: Yamcs RCE, FUXA pre-auth chain, and an npm `tmp` traversal pile onto XWiki + LiteSpeed
Late escalation at 21:00 ET adds a Yamcs algorithm-engine RCE, three pre-auth RCEs in FUXA, and a path traversal in the npm `tmp` transitive dep on top of the day's XWiki and LiteSpeed criticals.
Monday after the storm: TrapDoor's narrative spreads while two Defender CVEs land on KEV
Monday after the storm: TrapDoor's narrative spreads while two Defender CVEs land on the KEV list.
Four concurrent package-poisoning campaigns hit the registries at once
Four concurrent package-poisoning campaigns hit the registries at once.