AUTO-UPDATED

This Week in Security: Arch AUR, Steam Marketplace, WordPress All Face Issues, Taco-Themed Coding, and Mythos Makes National News

Multiple major software supply chain attacks have compromised the Arch User Repository, WordPress plugins, and Steam’s Wallpaper Engine, exposing millions of users to infostealer malware and unauthorized access.

Key Points

  • Attackers compromised over 1,500 Arch User Repository packages by hijacking abandoned projects to distribute infostealer malware via malicious NPM scripts.
  • A supply chain attack on Awesome Motive’s CDN impacted 1.2 million WordPress sites, allowing attackers to create hidden administrator accounts.
  • Malicious animated wallpapers on the Steam Workshop are currently distributing crypto miners, keyloggers, and remote access tools to unsuspecting users.
  • A 27-year-old vulnerability in OpenBSD’s PPP protocol allows unauthorized logins by exploiting improper length validation in authentication requests.
  • Anthropic has restricted public access to its Mythos AI model following government concerns regarding the model's ability to disclose sensitive cybersecurity information.

Why it Matters

These incidents highlight a growing trend where attackers exploit trusted software distribution channels to bypass traditional security defenses. As supply chain vulnerabilities become more frequent, organizations and individual users face increased risks from automated malware that can compromise entire systems through seemingly legitimate updates.
Hackaday Published by Mike Kershaw
Read original