Find a story

Search Spins

Search titles, summaries, and missing voices across published articles — press releases, announcements, and media coverage.

7 results for “supply chain attack”

SPIN Processed News Frame: The Hype

BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

A supply chain attack compromised BdThemes' WordPress plugins by injecting malicious JSON payloads that created unauthorized administrator accounts, without altering source code in the official WordPress.org repository.

Spin 45% Claim Present in Source AI Risk Moderate
The Hacker News

Aug 11, 2026

SPIN Processed News Frame: The Shield

QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer

A supply chain attack compromised QuickFox's Windows installer to deliver the FDMTP backdoor, targeting overseas Chinese users since at least August 2025.

Spin 65% Source-Supported AI Risk Moderate Needs Evidence
The Hacker News

Aug 5, 2026

SPIN Processed News Frame: The Fog

Keyv and friends compromised in active Shai-Hulud supply chain attack

A forum post on Hacker News reports unverified claims of a supply chain compromise involving Keyv and other projects under the 'Shai-Hulud' attack name, with no substantive details provided.

Spin 40% Needs Evidence
Hacker News Front Page

Aug 4, 2026

SPIN Processed News Frame: The Shield

Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers

Amazon attributed recent npm supply-chain attacks involving malicious packages 'Debug' and 'Chalk' to North Korean state-sponsored actors, positioning itself as a key threat intelligence contributor in open-source security.

Spin 75% Claim Present in Source AI Risk High
BleepingComputer

Jul 31, 2026

SPIN Processed News Frame: The Shield

When AppSec Scanners Become a Supply Chain Attack Vector

Security scanners integrated into software development pipelines can themselves be compromised to enable supply chain attacks, turning defensive tools into offensive vectors.

Spin 50% Needs Evidence AI Risk Moderate
Dark Reading

Jul 29, 2026

SPIN Processed News Frame: The Shield

GitHub, PyPI add time-absed defenses against supply chain attacks

GitHub and PyPI implemented time-based defenses in Dependabot to mitigate supply-chain attacks by limiting the window for malicious package substitution.

Spin 45% Claim Present in Source AI Risk Moderate
BleepingComputer

Jul 26, 2026

SPIN Processed News Frame: The Shield

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

A software supply chain attack named SleeperGem deployed three malicious RubyGems packages to compromise developer machines and deliver secondary payloads.

Spin 40% Claim Present in Source AI Risk Moderate
The Hacker News

Jul 20, 2026