The most notable supply-chain attacks of 2025
In 2025, just as in the year prior, supply-chain attacks remained one of the most severe threats facing organizations. We’re breaking down last year’s most noteworthy incidents.
11 articles
In 2025, just as in the year prior, supply-chain attacks remained one of the most severe threats facing organizations. We’re breaking down last year’s most noteworthy incidents.
In November 2025, the npm ecosystem was hit by a flood of junk packages that were part of the IndonesianFoods malicious campaign. We’re breaking down the lessons learned from this incident.
Unknown attackers have compromised several popular npm packages in a supply-chain attack.
Attackers are sending phishing emails to developers of PyPi packages and Firefox add-ons.
How to respond to a compromised GitHub changed-files Action incident.
The JavaScript CDN service Polyfill.io has started spreading malicious code. Remove the service’s script from your website.
A backdoor implanted into XZ Utils has found its way into popular Linux distributions.
Full review of a fake cryptowallet incident. It looks and feels like a Trezor wallet, but puts all your crypto-investments into the hands of criminals.
Unknown attackers tried to add a backdoor to PHP scripting language source code.
Even if you are really not an interesting target for an APT actor, you can still be used in a malware delivery chain