#supply-chain
// 11 transmissions tagged with #supply-chain

Malicious git hooks found in take‑home interview projects
CITIZENDOT uncovered git hooks hidden in interview code that steal SSH keys and other credentials, exposing candidates to a supply‑chain attack. The hooks install silently and give attackers persistent access to a developer’s machine.

npm v12 disables install scripts by default, requires allowScripts
npm v12 stops running preinstall, install, and postinstall scripts unless a package explicitly lists them in an allowScripts block. The open‑source npm‑script‑lens tool audits those scripts and surfaces their behavior for security review.

South Korea pledges $1 trillion for memory chips and humanoid robots
Seoul will pour $1 trillion into expanding memory‑chip capacity and building humanoid‑robot platforms, a push to secure semiconductor supply and boost automation.

Anonymous GitHub account mass‑drops undisclosed zero‑days
An anonymous GitHub account posted a repository of previously undisclosed zero‑day exploits, giving engineers a source to assess and patch vulnerable components [hn-front].

Apple seeks waiver to buy DRAM from blacklisted Chinese supplier CXMT
Apple has asked the U.S. government for a waiver to purchase DRAM from CXMT, a Chinese chipmaker on the Pentagon’s Entity List, citing a 30% price surge that would shave $15 billion from its 2026 margin.

Red Hat npm packages compromised, users urged to secure dependencies
A GitHub issue reports that several Red Hat npm packages have been compromised, exposing users to potential security risks. Red Hat is investigating and recommends immediate removal or audit of the affected packages.

FBI director Kash Patel's apparel site hosts clickfix malware
The website for FBI director Kash Patel's apparel brand is actively hosting a 'ClickFix' attack that tricks visitors into installing malware, PCMag reported May 23, 2026 [PCMag]. The malicious script was delivered through a third-party service on the site.

Memory shortage pushes smartphone prices up 15% in 2026
AI-driven memory demand has tightened supply, pushing average smartphone prices up 15% in 2026 and threatening the era of budget devices [davidoks.blog].

GitHub confirms breach via malicious VS Code extension
GitHub says attackers accessed 3,800 internal repos after compromising an employee device through a malicious VS Code extension [source: @appinventiv4ai].

Mini Shai-Hulud malware hits 314 npm packages
The Mini Shai-Hulud malware has compromised 314 npm packages by injecting obfuscated malicious code, according to SafeDep.

TanStack npm supply-chain compromise revealed
TanStack's postmortem analysis details the npm supply-chain compromise, caused by a vulnerable dependency in one of its packages [TanStack Blog]. The incident led to malicious code injection, affecting users.