Every watch, in order.
110 watches published so far. Each one captures what crossed the wire that day — new disclosures, fresh CISA KEV adds, package-hijack campaigns in progress — ranked by severity.
Two rclone advisories disclosed after First Watch show its S3 and RC auth-proxy checks can be bypassed outright, escalating a day that already had an unauthenticated RCE in OmniRoute and two new MikroTik KEV entries
Two rclone advisories disclosed after First Watch show its S3 and RC auth-proxy checks can be bypassed outright, escalating a day that already had an unauthenticated RCE in OmniRoute and two new MikroTik KEV entries.
Supply Chain Watch · 2026-09-09 — CISA's twin KEV adds for Citrix NetScaler and Cisco's firewall manager — both under three-day patch clocks — remain tonight's top priority, even after a late-evening batch of nine high-severity GHSA disclosures, including an MCP-server RCE and a LAN-exposed ESPHome dashboard, pushed the day's high count past every other evening this series has logged.
CISA's twin KEV adds for Citrix NetScaler and Cisco's firewall manager — both under three-day patch clocks — remain tonight's top priority, even after a late-evening batch of nine high-severity GHSA disclosures, including an MCP-server RCE and a LAN-exposed ESPHome dashboard, pushed the day's high count past every other evening this series has logged.
Supply Chain Watch · 2026-09-08 — Next.js and Astro's shared libheif AVIF RCE anchored the day, but CISA's evening KEV add of a pre-auth RCE in N-able N-central — MSP tooling with Kaseya-class blast radius — is the story that matters most before you log off.
Next.js and Astro's shared libheif AVIF RCE anchored the day, but CISA's evening KEV add of a pre-auth RCE in N-able N-central — MSP tooling with Kaseya-class blast radius — is the story that matters most before you log off.
Supply Chain Watch · 2026-09-07 — A 111-day-dormant Shai-Hulud payload walked straight past npm's malware scanner today, the same day Adobe's unpatched Magento zero-day was confirmed dropping a disguised Rust backdoor on live stores.
A 111-day-dormant Shai-Hulud payload walked straight past npm's malware scanner today, the same day Adobe's unpatched Magento zero-day was confirmed dropping a disguised Rust backdoor on live stores.
Supply Chain Watch · 2026-09-06 — A quiet day on the new-item front, but the two open threads from earlier in the week kept getting worse in the details: the fake-Claude-Desktop stealer campaign grew persistence modules that survive its own cleanup, and Magento/Adobe Commerce store operators are into a second day with zero vendor fix for StyleSmuggler.
A quiet day on the new-item front, but the two open threads from earlier in the week kept getting worse in the details: the fake-Claude-Desktop stealer campaign grew persistence modules that survive its own cleanup, and Magento/Adobe Commerce store operators are into a second day with zero vendor fix for StyleSmuggler.
Supply Chain Watch · 2026-09-05 — A live, unauthenticated, patch-less Magento zero-day landed the same afternoon a Switchvox KEV hit its remediation deadline — one bug you can still fix, one you can only shield.
A live, unauthenticated, patch-less Magento zero-day landed the same afternoon a Switchvox KEV hit its remediation deadline — one bug you can still fix, one you can only shield.
Supply Chain Watch · 2026-09-04 — A last-minute KEV add stole the night from the AI-agent story — CISA confirmed active exploitation of a Chromium V8 type-confusion bug just as GPT-6 Astra and eight CodeWhale approval-bypass CVEs showed agents landing on both sides of the supply chain today.
A last-minute KEV add stole the night from the AI-agent story — CISA confirmed active exploitation of a Chromium V8 type-confusion bug just as GPT-6 Astra and eight CodeWhale approval-bypass CVEs showed agents landing on both sides of the supply chain today.
Supply Chain Watch · 2026-09-03 — SiYuan's publish-mode disclosures kept escalating after First Watch and capped the night with an unauthenticated, stored SQL injection reachable from a saved document title.
SiYuan's publish-mode disclosures kept escalating after First Watch and capped the night with an unauthenticated, stored SQL injection reachable from a saved document title.
Supply Chain Watch · 2026-09-02 — A late four-CVE OpenChoreo disclosure — headlined by an unauthenticated cluster-gateway bypass — landed alongside a second Omnigent guardrail failure, turning today's AI-agent execution-layer story into a platform-trust story before midnight.
A late four-CVE OpenChoreo disclosure — headlined by an unauthenticated cluster-gateway bypass — landed alongside a second Omnigent guardrail failure, turning today's AI-agent execution-layer story into a platform-trust story before midnight.
Supply Chain Watch · 2026-09-01 — A grind of a disclosure day — pnpm, browserslist, MLflow, and Filament all shipped fixes for install- and load-time supply-chain primitives, but no new active campaign or CISA KEV entry landed to go with them.
A grind of a disclosure day — pnpm, browserslist, MLflow, and Filament all shipped fixes for install- and load-time supply-chain primitives, but no new active campaign or CISA KEV entry landed to go with them.
Supply Chain Watch · 2026-08-31 — A pre-auth PaperCut RCE chain still owns tonight's operational priority, but a Kirby CMS security release landing after First Watch — two high-severity fixes for an auth'd storage-exhaustion bug and an encoded-slash path traversal — escalated the day's disclosure count late.
A pre-auth PaperCut RCE chain still owns tonight's operational priority, but a Kirby CMS security release landing after First Watch — two high-severity fixes for an auth'd storage-exhaustion bug and an encoded-slash path traversal — escalated the day's disclosure count late.
Supply Chain Watch · 2026-08-30 — The registries went quiet, but this month's infostealer wave turned up draining Claude session cookies instead of crypto wallets
The registries went quiet today, but the same commodity infostealers behind this month's ClickFix wave turned up draining Claude session cookies instead of crypto wallets.
Supply Chain Watch · 2026-08-29 — Spoofable client headers undo access control across three unrelated projects while Plone takes the day's only critical slot
Spoofable client headers undo access control in three unrelated projects today, while Plone takes the day's only critical slot with a matched pair of import-triggered SSRF/DoS/XSS bugs.
Supply Chain Watch · 2026-08-28 — Mini Shai-Hulud hits an npm codegen package with valid provenance, Pimcore ships a five-CVE editor-to-RCE chain, and a late GHSA batch adds a RestrictedPython sandbox bypass
A Shai-Hulud-style npm worm hit a widely-used TanStack Query codegen package with valid provenance attestations, Pimcore shipped five same-day advisories chaining editor access to server RCE, and a late GHSA batch added a RestrictedPython sandbox-guard bypass and a SeaweedFS bucket-isolation break.
Supply Chain Watch · 2026-08-27 — Crossplane's signature-check bypass and an Artifactory KEV add crack the package-integrity tooling itself
Today's fault lines run through the machinery meant to guarantee package integrity — a signature-verification bypass in Crossplane and a path-traversal KEV add in JFrog Artifactory — even as Australian police close the book on March's scanner-compromise campaign.
Supply Chain Watch · 2026-08-26 — A live PyPI credential-stealer campaign meets the MCP ecosystem's spreading trust-boundary bug
A live PyPI credential-stealer campaign and an unauthenticated LIMS RCE land the same day the MCP-tooling ecosystem's trust-boundary bug spreads to a seventh project.
Supply Chain Watch · 2026-08-25 — The MCP server ecosystem's worst disclosure day yet
The MCP server ecosystem had its worst disclosure day yet: a dozen-plus agent-tooling projects — PraisonAI, Chainlit, mcp-shell, utcp, qwed-mcp, and more — dropped auth-bypass, SSRF, or RCE advisories within hours of each other.
Supply Chain Watch · 2026-08-24 — An Oracle KEV add anchors a day of broken authorization logic across CMS, LMS, and proxy panels
CISA's KEV add for an actively-exploited Oracle proxy flaw anchored a day otherwise defined by broken authorization logic — cached-state bypasses, missing ownership checks, and unconfined admin inputs — across CMS, LMS, and proxy-panel software.
Supply Chain Watch · 2026-08-23 — A dark board
A dark board: three passes, three feeds, zero items that cleared the bar.
Supply Chain Watch · 2026-08-22 — BADBOX-linked group turns Android car head units into a proxy botnet
A day light on new disclosures narrowed to a single story: a BADBOX-linked group turned automotive Android head-unit firmware into a residential proxy botnet.
Supply Chain Watch · 2026-08-21 — JSONata, Xinference, Phalcon, and GeoTools RCEs land together; RedC2 npm backdoor and Zimbra hit KEV
A late-evening dump of four unrelated critical RCEs — JSONata, Xinference, Phalcon, and GeoTools — landed alongside a fresh npm backdoor campaign and a newly-KEV'd Zimbra pre-auth command injection.
Supply Chain Watch · 2026-08-20 — Hijacked crates.io account drops build-time payload in three Rust crates, TrueConf hits KEV
A compromised crates.io maintainer account slipped a build-time payload into three widely used Rust crates — the same postinstall-dropper playbook that's hit npm repeatedly this year, now proven out in Cargo.
Supply Chain Watch · 2026-08-19 — MCP-server disclosure cluster, Copier trust bypass, MLflow SSRF hits CISA KEV
Six MCP-server disclosures in one hour turned the AI-agent tooling layer into today's supply-chain story, while CISA confirmed active exploitation of an MLflow SSRF flaw.
Supply Chain Watch · 2026-08-18 — four-vendor CISA KEV cluster, RubyGems StubMaker resurfaces, late LibreNMS SSRF-XSS
A four-vendor CISA KEV cluster — Microsoft twice, VMware, and Apple — lands the same day RubyGems' StubMaker typosquat campaign resurfaces, capped by a late LibreNMS SSRF-to-stored-XSS disclosure batch.
Supply Chain Watch · 2026-08-17 — vm2 sandbox escapes, MLflow SSRF, uniget signature bypass
vm2 — the Node.js sandbox library agent tooling still leans on to run untrusted code — took five new disclosures in one batch, three of them full escapes that bypass its own documented defenses.
Supply Chain Watch · 2026-08-16 — A Quiet Day, One ClickFix Infostealer Update
A rare quiet day on the supply chain front — the only new signal was a macOS infostealer bolting live browser-session hijacking onto its ClickFix playbook.
Supply Chain Watch · 2026-08-15 — A Quiet Saturday, Yesterday's MCP Cluster Still the Live Thread
A quiet Saturday: no new GHSA advisories, no active-campaign reports, and no fresh CISA KEV adds since Tuesday.
Supply Chain Watch · 2026-08-14 — MCP Servers Become the Attack Surface
Three separate advisories landed against MCP server implementations today — a shell-injection RCE and an unauthenticated path traversal in the same npm MCP tool, plus a DNS-rebinding SSRF bypass in an MCP gateway.
Supply Chain Watch · 2026-08-13 — AI-Agent Stack's Bad Day, Metabase KEV Deadline Tomorrow
The AI-agent stack disclosed four unrelated bugs in one day, and a backfilled Metabase KEV entry hits its federal patch deadline tomorrow.
Supply Chain Watch · 2026-08-10 — Poisoned Side-Channels Hit VS Code and WordPress
Two unrelated ecosystems — VS Code extensions and WordPress plugins — got hit by the same trick today: poison the trusted side-channel a package polls, not the package itself.
Supply Chain Watch · 2026-08-09 — A Rare Quiet Sunday Across GHSA, KEV, and the Campaign Feeds
A rare quiet Sunday: no new GHSA advisories, no active-campaign reports, and no fresh CISA KEV adds in the last six hours.
Supply Chain Watch · 2026-08-08 — Six-Advisory GitPython RCE Batch and a Four-Bug CodeIgniter Wave Land as a Six-Year-Old crypto-js Weak-RNG Bug Is Confirmed Draining Wallets
Six coordinated GitPython option-injection RCEs and a four-bug CodeIgniter batch dropped the same day Coinspect confirmed a six-year-old crypto-js weak-RNG bug has been silently seeding real wallets.
Supply Chain Watch · 2026-08-07 — A ~800-Package npm Dropper Campaign Lands Alongside Critical CodeIgniter RCE Bugs and a Fast-Tracked LoadMaster KEV
A near-800-package npm dropper campaign lands the same day CodeIgniter ships two critical RCE-class bugs and CISA fast-tracks a LoadMaster command-injection KEV add.
Supply Chain Watch · 2026-08-06 — Traefik and Craft CMS Chain to Auth Bypass; Late PHP_CodeSniffer and pdf.js Disclosures Close the Day
Traefik's auth-bypass batch and Craft CMS's password-reset-to-RCE chain anchored the day, then a late PHP_CodeSniffer CI command injection and a pdf.js scripting bug closed it out.
Supply Chain Watch · 2026-08-05 — A KEV-Listed TeamCity RCE and a Critical Nuxt DevTools Bug Bookend a Backlog-Clearing Day
A KEV-listed TeamCity RCE and a critical unauthenticated Nuxt DevTools RCE bookend a day otherwise dominated by GHSA clearing a massive disclosure backlog across Ghost, Electron, Nuxt, and rclone.
Supply Chain Watch · 2026-08-04 — An npm Worm Hits keyv While Flowise Absorbs 23 CVEs
A self-propagating npm worm tore through the keyv and cacheable namespaces the same day GHSA published Flowise's entire disclosure backlog — 23 CVEs — plus a fresh six-bug Open WebUI batch, making it open season on AI-agent tooling.
Supply Chain Watch · 2026-08-03 — An npm RAT Campaign Against Alibaba, and a Host-Parsing Bug Rediscovered Three Times
A three-month-old, still-live RAT campaign targeting Alibaba's internal npm tooling surfaced the same day two dozen disclosures landed across Python, PHP, JavaScript, and Rust — three of them the same host-parsing bug independently rediscovered in Guzzle, ip-address, and fast-uri.
Supply Chain Watch · 2026-08-02 — A Completely Quiet Day
All three passes today came back empty — no new CISA KEV entries, no in-scope GHSA disclosures, and nothing from the active-campaign feeds — a hard stop after yesterday's ApostropheCMS authorization-bypass bug.
Supply Chain Watch · 2026-08-01 — ApostropheCMS prototype pollution collapses into a process-wide auth bypass
A single prototype-pollution bug in ApostropheCMS quietly disables every authorization check on the platform — the sharpest edge in an otherwise broad day of input-trust failures across CMS, payment, and infrastructure tooling.
Supply Chain Watch · 2026-07-31 — Adform ad-script crypto-clipper + Apostrophe's three-package trust-boundary failure
A live ad-script supply chain attack is siphoning cryptocurrency from every site running Adform's tags, landing the same day as five critical disclosures — a CMS, a low-code platform, a Kubernetes admission webhook, a game-hosting daemon, and AWS Amplify — plus a late-arriving second and third Apostrophe advisory showing the CMS's trust-boundary problem wasn't a one-off.
Supply Chain Watch · 2026-07-30 — Rails Active Storage RCE + flyto-core's SSRF meltdown
A default-config Rails RCE and a six-CVE meltdown in an AI workflow framework landed the same day Amazon confirmed North Korea authored last year's record npm hijack.
Supply Chain Watch · 2026-07-29 — The swagger-typescript-api Six
swagger-typescript-api became today's spec-to-RCE story: six advisories show a hostile OpenAPI document can inject code into its own generated client, echoing yesterday's datamodel-code-generator pile-up almost exactly one day later.
Supply Chain Watch · 2026-07-28 — The datamodel-code-generator Dozen
The day's headline event stayed datamodel-code-generator's eleven-advisory pile-up, but a late batch after First Watch pushed goshs to five separate advisories in one day and added an unrelated critical SQL injection in @hypequery/clickhouse — 21:00 didn't mean the day was done.
Supply Chain Watch · 2026-07-26 · A Quiet Sunday, Except for Dependabot's New Cooldown Window
The only story of the day was a defensive one — GitHub and PyPI shipped a built-in cooldown window for Dependabot, and nothing else moved.
Supply Chain Watch · 2026-07-25 · Budibase, Poweradmin, and blaze Batch the Day, Then a Predictable-Key Critical Lands Late
The day's shape is the partial fix — GitPython and Pheditor both got hit again by the same bug class a prior patch was supposed to have closed, while six other platforms dropped chained multi-CVE batches in a single shot.
Supply Chain Watch · 2026-07-24 · Budibase, OpenAM/OpenDJ, and a Late Shescape Escape-Bypass Critical
A fourth critical landed after First Watch — npm shell-escaping library Shescape ships its own shell-injection bypass on Windows CMD — capping a day that already saw seven criticals across Budibase and OpenAM/OpenDJ.
Supply Chain Watch · 2026-07-23 · Two Auth.js Criticals, A Quiet Batch Behind Them
Two Auth.js advisories that can silently disable authentication anchor a day otherwise dominated by open redirects and memory-exhaustion bugs — React Router's four-advisory redirect-hardening batch, a paired pypdf infinite-loop fix, and a fresh PHPSpreadsheet SSRF bypass — with nothing yet confirmed under active attack.
Supply Chain Watch · 2026-07-22 · A four-wave Wednesday — Gitea, n8n twice, Netty, Next.js, Jetty, JupyterLab, LiteLLM — plus two KEV criticals
Late escalation at 21:00 ET: a fourth disclosure wave — 50 more advisories spanning a second n8n batch plus first-time appearances from Next.js, Eclipse Jetty, JupyterLab, and LiteLLM — landed within 75 minutes of the day's 18:00 synthesis, pushing the day's total past 135 items and its high-severity count past 55.
Supply Chain Watch · 2026-07-21 · A 21-advisory Gitea disclosure lands on a KEV-heavy day
A single coordinated disclosure dropped 21 Gitea advisories in about two hours — four critical, including a Docker image default that hands any network attacker admin — on top of a KEV day already carrying a live WordPress SQLi-to-RCE chain.
Supply Chain Watch · 2026-07-20 · A 90-advisory GHSA wave overshadows SleeperGem's RubyGems hijack
A same-day GHSA wave that ran from 6pm to past 9pm ET eventually reached 90 advisories, overshadowing SleeperGem's quiet RubyGems hijack — headlined by a critical node-tar bug reachable through every npm install, a Composer bug that lets a malicious transitive dependency write files outside vendor/, and a second, equally large round of Pillow, Axios, and .NET disclosures that landed after First Watch had already gone to print.
Supply Chain Watch · 2026-07-19 · SleeperGem's dormant-account hijack on RubyGems, on an otherwise quiet Sunday
SleeperGem's dormant-maintainer-account hijack on RubyGems was the day's lone confirmed supply-chain hit, on an otherwise quiet Sunday.
Supply Chain Watch · 2026-07-18 · A quiet Saturday, one escalation
The only development on an otherwise silent Saturday was ACR Stealer's ClickFix campaign graduating from a researcher writeup to a vendor-confirmed, enterprise-scale surge.
Supply Chain Watch · 2026-07-17 · ViteVenom and the sibling-path pattern
A blockchain-controlled npm campaign returns as ViteVenom, while five unrelated projects each shipped a patch that admitted its first fix missed the vulnerability's sibling path.
Supply Chain Watch · 2026-07-16 — Trojanized installers, a self-propagating npm worm, and two same-day KEV adds
A trojanized-installer campaign, a self-propagating npm worm, and two same-day CISA KEV adds converged today — each one weaponizing a channel defenders trust by default.
Supply Chain Watch · 2026-07-15 — A late Datadog six-language tracer DoS and a ViewComponent XSS bypass push the day past 30 highs
MantisBT's zero-password admin takeover held the day's top story, but a 9pm wave of 22 GHSA advisories — a six-language Datadog tracer DoS, a Rails ViewComponent XSS bypass, and a django-haystack eval() RCE — pushed the day's high-severity count past 30.
Supply Chain Watch · 2026-07-14
A pile-up day: four new FacturaScripts advisories, three same-root-cause Anyquery RCE-class bugs, and three separate MCP-server disclosures landed alongside two live GitHub/npm impersonation campaigns and four newly-confirmed CISA KEV exploits.
Supply Chain Watch · 2026-07-13 — A late Kimai Docker-secret account takeover and a brute-forceable FacturaScripts 2FA bypass escalate the day to five criticals
A late 21:00 ET wave adds two more confirmed-exploitable criticals — a hardcoded Docker default secret enabling Kimai account takeover and a brute-forceable FacturaScripts 2FA bypass — on top of a day that already carried a newly-exploited legacy Cisco IOS bug, DIRAC's double eval()-to-RCE disclosure, and day three of the unresolved jscrambler npm infostealer.
Supply Chain Watch · 2026-07-12 — An all-quiet edition, with yesterday's jscrambler MCP-credential infostealer still the only live thread
A rare all-quiet stretch: three straight passes today turned up nothing new, leaving yesterday's jscrambler MCP-credential infostealer as the only thread still worth chasing.
Supply Chain Watch · 2026-07-11 — A compromised jscrambler npm release ships a Rust infostealer that specifically hunts Claude Desktop, Cursor, and other MCP configs
A compromised jscrambler npm release spent three hours mutating past its own install-hook detection while its Rust infostealer went straight for Claude Desktop, Cursor, and other MCP server credentials.
Supply Chain Watch · 2026-07-10 — SiYuan answers YesWiki's 13-advisory morning with 7 of its own, three RCE chains deep, while a compromised Injective Labs repo ships a wallet-stealing npm package
A second coordinated multi-CVE batch — seven SiYuan advisories with three independent RCE chains — landed hours after this morning's YesWiki disclosure, while a compromised Injective Labs GitHub repo pushed a wallet-draining npm package into the wild.
Supply Chain Watch · 2026-07-09 — Wallet and payment SDKs hit across three ecosystems, YesWiki takes a 13-advisory teardown, then a late Elixir HTTP-client batch lands after bed-check
Late escalation at 21:00 ET: a fresh GHSA batch lands three more high-severity disclosures — header-leak and memory-exhaustion bugs across Elixir's two workhorse HTTP clients, Tesla and Mint — on top of a day already shaped by a three-ecosystem wallet/payment-credential wave and a 13-advisory YesWiki teardown.
Supply Chain Watch · 2026-07-08 — Agentic tooling's authless-API problem
Five unrelated AI-agent and MCP-adjacent tools — Langflow, Open WebUI, ha-mcp, ckan-mcp-server, and Serena — disclosed authorization or authentication gaps on the same day, the clearest sign yet that agentic tooling is shipping with the auth debt web frameworks paid off a decade ago.
Supply Chain Watch · 2026-07-06 — Late Escalation: Zcash Circuit Bug Caps a Nine-Advisory Day
Zebra disclosed a CVSS-9.3 soundness bug in Zcash's Orchard shielded-pool circuit at 21:00 ET, a late critical escalation onto a day that had already produced four separate critical dev-and-agent-tooling disclosures.
Supply Chain Watch · 2026-07-05 — A Quiet Day, Start to Finish
Nothing broke: no new CISA KEV entries, no GHSA advisories in scope, and no active-campaign writeups from Socket, Phylum, Hacker News, BleepingComputer, or Aikido across all three passes today.
PolinRider Keeps Scaling, and Little Else Broke
The DPRK-linked PolinRider campaign is now up to 108 malicious packages and browser extensions across four ecosystems, and it's the only story of the day — KEV, GHSA, and the rest of the RSS feeds stayed quiet.
Six Projects, One Coordinated-Disclosure Day
Six unrelated open-source projects each shipped a coordinated multi-CVE batch today, from Steeltoe's seven advisories to Zebra's twelve, while the MCP-gateway trust-boundary bug count for the week climbed to four.
Six MCP/agent-gateway projects disclose auth bugs in a day, Mautic and LaunchServer land unauth RCE-adjacent criticals
Six unrelated MCP and agent-gateway projects disclosed authorization or credential-handling bugs in the same 24 hours, making the agent-tooling trust boundary — not any single campaign — today's story.
PolinRider spreads to a fourth ecosystem, Rancher/SurrealDB/Sigstore dump mass disclosures, then two late MCP/DB credential-leak bugs land before bed
A North Korea-linked campaign expanded to a fourth ecosystem and Rancher, SurrealDB, and Sigstore all dropped mass-disclosure batches — then, in the final hour before bed, two more high-severity credential-leak bugs landed in an Apify MCP server and a Postgres SCRAM client.
Registry to trust root: a PyPI backdoor, a Fission node-escape pileup, and an SSRF in Sigstore's CA
A live PyPI backdoor campaign, a coordinated node-escape pileup in Fission's serverless platform, and an SSRF in Sigstore's signing CA hit every layer from registry to trust root on the same day.
Supply Chain Watch · 2026-06-29 — Stealers ride the trusted channels; SimpleHelp hits the KEV
Infostealers keep arriving through trusted channels — hijacked npm/Go packages, a KEV-listed SimpleHelp auth bypass, and a late wave of clipboard-stealing browser extensions — while OpenAM and Dgraph patch server-side identity and injection flaws.
Supply Chain Watch · 2026-06-28 — A quiet registry day exposes the AI coding agent's config as the new injection point
A quiet day on the registries threw the week's real shift into relief: both of today's disclosures weaponize the AI coding agent's auto-trusted setup surface — repo configs and MCP definitions — rather than any poisoned package.
Supply Chain Watch · 2026-06-27 — The worm reaches the credential brokers, and the day rhymes on one flaw
The Miasma worm crossed from npm into Backstage's GitLab and LDAP auth plugins, Polymarket lost roughly $3M to a poisoned frontend, and a wave of disclosures — Nezha, pnpm, Hackney, ex_aws_sns — all rhymed on one flaw: trusting attacker-controlled input as authorization.
Supply Chain Watch · 2026-06-26 — The worm spreads, the wheel rots, and pnpm becomes the attack surface
A self-replicating npm worm jumped to its third package set and a poisoned PyPI wheel harvested the same credentials by other means — then a late coordinated pnpm disclosure turned the package manager itself into the attack surface.
golang.org/x/crypto/ssh breaks open late on a Go-heavy day
A late coordinated disclosure cracks the golang.org/x/crypto/ssh stack open — a CVSS-10 public-key auth bypass and five more critical SSH/agent flaws — onto a day already defined by Shai-Hulud crossing into Go and OpenAM's five-way collapse.
OpenAM identity stack takes a third hit as three CVSS-10 RCEs open the day
Three CVSS-10 RCEs opened the day; a chainable pair of pre-auth OpenAM criticals closed it, making the identity stack the story two days running.
Supply Chain Watch · 2026-06-23 — Identity takes the brunt; late Snipe-IT tenancy batch
Identity infrastructure took the brunt — pre-auth RCE in OpenDJ, pre-auth XSS and LDAP injection in OpenAM, and LastPass breached through stolen OAuth tokens — while npm typosquats dropped a Windows RAT, CISA logged four exploited appliance flaws, and a late Snipe-IT disclosure batch added a cross-tenant data injection after the bell.
Supply Chain Watch · 2026-06-22 · The trusted update channel was the attack
The trusted update channel was the attack: ShapedPlugin shipped a CVSS-10 backdoor through official Pro-plugin releases for a month — and the evening brought a late wave of forge and npm-library disclosures, capped by a fresh SCIM prototype-pollution critical.
Supply Chain Watch · 2026-06-21 — A quiet Sunday on the registries
A quiet Sunday on the registries — no new criticals and no fresh KEV adds, leaving the day's only live thread an actively-exploited WordPress plugin leaking the API keys and OAuth tokens that downstream attacks usually have to phish for.
Supply Chain Watch · 2026-06-20 — A state actor claims the Mastra compromise
Microsoft pinned last week's 140-package Mastra AI npm compromise on North Korea's BlueNoroff while the agent stack kept failing in public — a third critical-class Langflow hole now on CISA KEV, fresh cross-tenant breaks in the agent-memory stores, and another MCP-server SSRF and path-traversal cluster.
Supply Chain Watch · 2026-06-19 — The agentic toolchain audits itself in public
The agentic toolchain audited itself in public all day — Langflow and Network-AI criticals, an MCP-server SSRF/XSS cluster, and cross-tenant breaks across the agent-memory stores — and kept going after dark with a LangSmith SDK file-read and a Lokka MCP Azure-token leak.
Supply Chain Watch · The agent ecosystem's bad day
AI agent frameworks and MCP servers became the day's soft target — a dozen-plus unauthenticated-control-plane and prompt-injection-to-RCE holes landed across PraisonAI, Crawl4AI, OpenClaw and the MCP tooling, while a real update-channel compromise hit WordPress and CISA flagged an actively-exploited Splunk file-write.
Supply Chain Watch · 2026-06-17 · The AI toolchain is the supply chain
The AI development toolchain became the supply chain: two live npm and IDE credential-theft campaigns landed alongside a flood of fresh advisories against the self-hosted LLM stack.
Supply Chain Watch · 2026-06-16 — AI-stack mass disclosure escalates after dark: Rclone unauth RCE, LiteLLM auth bypass, n8n CVSS-10 browser hole & cross-tenant cred takeover, Gitea/Gogs token-scope bypasses
The day escalated after dark: unauthenticated RCE in Rclone, an auth bypass in the LiteLLM proxy, a CVSS-10 unauthenticated browser-control hole and cross-tenant credential takeover in n8n, and a token-scope-bypass cluster across Gitea and Gogs piled onto the AI-development-stack mass disclosure and the IDE plugins caught stealing AI keys.
Supply Chain Watch · 2026-06-15 — Live WordPress CDN supply-chain attack, dev-tooling RCE, two KEV adds
A live CDN supply-chain attack on three widely-deployed WordPress plugins headlines a day of dev-tooling RCE and fresh CISA KEV adds.
A quiet registry day, and a decade-long auth-stack hijack
A rare quiet day across the registries, with the lone headline a decade-long hijack of a target's authentication stack that reframes identity as the supply chain's deepest dependency.
File Browser empties its disclosure queue
The week's File Browser disclosure run crests with six advisories dropped at once — unauth share leaks, a one-packet login DoS, zip-slip and symlink escapes — while esbuild's Deno installer quietly reopens a build-time RCE path.
Supply Chain Watch · 2026-06-12 — The AUR burns while the frameworks patch
Four hundred-plus Arch AUR packages are poisoned with an infostealer and eBPF rootkit on the same day Budibase, TYPO3 and File Browser ship coordinated emergency mass-patches.
Supply Chain Watch · 2026-06-11 — npm moves to disarm install scripts as a supply-chain worm's source leaks
npm moves to disarm install scripts on the same day a supply-chain worm's source code leaks and PDM lands its second code-execution flaw — the install-time attack surface is the whole story.
KEV deadline day, Miasma source leak, Claude Code Action MCP flaw — Supply Chain Watch 2026-06-10
CISA KEV deadlines for TanStack and Nx Console land today as Miasma's source code briefly leaks on GitHub and a new supply-chain vector — malicious MCP server config in pull requests — puts Claude Code Action CI pipelines at risk of secret exfiltration.
Self-propagating PyPI worms, five CISA KEVs, and a late Dex/PhoenixStorybook RCE wave
A late GHSA wave after 18:00 ET delivered unauthenticated RCE in PhoenixStorybook and a connector-ACL bypass in Dex, extending a day already shaped by the Shai-Hulud PyPI worm campaign and five CISA KEV additions.
Supply Chain Watch · Late KEV escalation — LiteLLM RCE caps a developer-toolchain day
A 21:00 ET KEV addition dropped a command-injection RCE in the open-source LiteLLM gateway onto the actively-exploited list — capping a day already shaped by two ransomware-linked developer-toolchain compromises, Nx Console and TanStack.
Supply Chain Watch · A quiet Sunday with one loud exception: Miasma's PyPI wave
The disclosure feeds went silent for the weekend, leaving one story standing: Miasma opened a Python propagation arm — 37 malicious PyPI wheels that execute on interpreter start, no import required.
Supply Chain Watch · Miasma reaches Microsoft's GitHub orgs, and DbGate hands over a CVSS 10
The Miasma worm crossed from npm into Microsoft's own GitHub estate — 73 repositories disabled across four organizations — while DbGate disclosed an unauthenticated CVSS-10 RCE.
Supply Chain Watch · A worm joins IronWorm on npm, and two KEV clocks run down
IronWorm's npm campaign doubles to 50-plus poisoned packages and picks up a self-spreading worm and a kernel rootkit, while CISA's KEV clock runs out on a Magento RCE tonight.
Supply Chain Watch · Two npm Worms and a Jupyter Cluster-Takeover
Two self-propagating npm worms hit the registry the same day a triple-critical SSTI flaw turns Jupyter's Kubernetes gateway into full cluster takeover.
Supply Chain Watch · 2026-06-03 — Developer-environment day: VS Code token steal, Jupyter K8s RCE trio, four KEV adds in 48 hours
A public VS Code / github.dev one-click token steal and a triple-critical RCE chain in Jupyter Enterprise Gateway land in the same 48-hour window CISA pushes four bugs to the KEV catalog and Wordfence logs hundreds of active hits on Kirki.
Two Vitest CVEs and a six-advisory praisonai cluster push developer tools into scope while CISA stacks three KEV adds
Two Vitest CVEs, six praisonai IDORs, and a conda write-anywhere push developer tooling into the day's attack surface while CISA stacks three KEV adds on top.
Supply Chain Watch · Mini Shai-Hulud worms into Red Hat's npm scope · 2026-06-01
Mini Shai-Hulud lands inside Red Hat's official npm scope — the trusted-vendor namespace compromise the ecosystem has been preparing for since last summer.
Famous Chollima moves to Packagist as KEV-backlog day winds down
DPRK's Contagious Interview crew ports its npm playbook to PHP, dropping malware in a Packagist-listed package on an otherwise quiet KEV-burndown Sunday.
Ghost CMS RCE backdoors 700+ dev sites with ClickFix; CISA hands PAN-OS a 72-hour clock; AI CLIs still trust the working directory
Developers are the day's target — a Ghost CMS RCE has backdoored 700+ tech and university sites into ClickFix droppers, CISA hands PAN-OS a 72-hour patch clock, and another AI-coding CLI ships with implicit working-directory trust.
Supply Chain Watch · 2026-05-29
Late escalation at 21:00 ET: a 19-advisory audit dump against PraisonAI lands on top of the morning's vm2/Redshift/Gotenberg trio — official A2A example reaches unauthenticated `eval()`, `deploy --type api` ships with auth disabled, and Platform's JWT key defaults to a hardcoded `dev-secret-change-me`.
Sicoob banking-SDK NuGet impersonator exfiltrates certs through Sentry; Symfony tops twenty advisories; paired Dulwich RCEs land late
A Sicoob banking-SDK impersonator on NuGet exfiltrates client certs through Sentry, the Symfony tranche tops twenty advisories, and a late-evening paired Dulwich disclosure revives the NTFS-hostile-tree-entry class on Windows.
CISA KEV-lists Nx Console + TanStack as the npm wave goes federal; Yamcs ships two mission-control RCEs
CISA closes the day with KEV adds for Nx Console and TanStack — turning the npm credential-stealing wave into a federal-mandate clock — while Yamcs hands aerospace operators two critical mission-control RCEs.
Late escalation: Yamcs RCE, FUXA pre-auth chain, and an npm `tmp` traversal pile onto XWiki + LiteSpeed
Late escalation at 21:00 ET adds a Yamcs algorithm-engine RCE, three pre-auth RCEs in FUXA, and a path traversal in the npm `tmp` transitive dep on top of the day's XWiki and LiteSpeed criticals.
Monday after the storm: TrapDoor's narrative spreads while two Defender CVEs land on KEV
Monday after the storm: TrapDoor's narrative spreads while two Defender CVEs land on the KEV list.
Four concurrent package-poisoning campaigns hit the registries at once
Four concurrent package-poisoning campaigns hit the registries at once.