Multiple major software supply chain attacks have compromised the Arch User Repository, WordPress plugins, and Steam’s Wallpaper Engine, exposing millions of users to infostealer malware and unauthorized access.
Key Points
- Attackers compromised over 1,500 Arch User Repository packages by hijacking abandoned projects to distribute infostealer malware via malicious NPM scripts.
- A supply chain attack on Awesome Motive’s CDN impacted 1.2 million WordPress sites, allowing attackers to create hidden administrator accounts.
- Malicious animated wallpapers on the Steam Workshop are currently distributing crypto miners, keyloggers, and remote access tools to unsuspecting users.
- A 27-year-old vulnerability in OpenBSD’s PPP protocol allows unauthorized logins by exploiting improper length validation in authentication requests.
- Anthropic has restricted public access to its Mythos AI model following government concerns regarding the model's ability to disclose sensitive cybersecurity information.