Attackers use Web3 smart contracts in cloud supply chain hacks
Threat actors are adopting decentralized Web3 smart contracts as command-and-control infrastructure in recent software supply chain attacks, allowing dynamic updates of malware networks. Campaigns like ChainDrop and PolinRider have compromised open-source dependencies to steal cloud access keys and persist within developer workflows. North Korea-linked groups have used these methods to target companies including Axios and Mastra AI. Open-source and CI/CD pipelines remain a significant risk point for enterprise cloud security.
- Threat actors use smart contracts for malware command-and-control
- ChainDrop infected over 400 npm packages
- Campaigns target cloud credentials via open-source poisoning
- North Korea-linked groups implicated in recent attacks
- CI/CD and developer endpoints are a main target
Sources covering this
More in Cybersecurity
Four states sue TP-Link over router security claims
Florida and three other US states have filed lawsuits against TP-Link, alleging the company misled consumers about its routers' security…
Outlook will block MSIX file attachments in November
Microsoft will begin blocking .msix and .msixbundle attachments in Outlook on the web and the new Outlook for Windows starting in November.
Major software vendors patch critical vulnerabilities
Cisco Talos researchers reported multiple vulnerabilities in products from Microsoft, Adobe, Apple, and Foxit.
PoeLLM malware builds botnet targeting AI services
Researchers have identified malware named PoeLLM that has compromised over 3,400 servers since April by targeting open-source AI services.