[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fqGfqQ9rpz2xSdkR9l65GcbJqbgxqNoJ6Gg8e7XJ_bRQ":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"8ea986b3-025e-4317-9237-04f45d28af85","malicious-packages-fake-extensions-fuel-multi-vector-supply-chain-threats","41a22f8b-dbfd-4281-a9cf-5aec8f02800b","Malicious Packages & Fake Extensions Fuel Multi-Vector Supply Chain Threats","This week's threat landscape demonstrates how attackers are increasingly weaponizing trusted developer ecosystems — npm packages, VS Code extensions, and PyPI repositories — to deliver malware, steal credentials, and execute arbitrary commands. The root cause lies in insufficient vetting of third-party code and a lack of developer awareness around the risks of open-source dependencies. Malicious actors impersonate legitimate tools to exploit the inherent trust developers place in popular package registries, making detection difficult without proactive controls. The targeting of Portuguese banking users and macOS systems further illustrates that these threats span platforms, audiences, and sectors. Without systematic dependency auditing and supply chain hygiene, organizations remain highly exposed to these low-cost, high-impact attack vectors.","**Immediate actions:**\n- Audit all active npm, PyPI, and VS Code extension dependencies for known-malicious or recently-published packages using tools like Socket.dev or OSV Scanner.\n- Remove or quarantine any unverified third-party extensions or packages from developer workstations and CI\u002FCD pipelines immediately.\n\n**Long-term improvements:**\n- Establish a software composition analysis (SCA) process that automatically scans dependencies on every build and pull request.\n- Enforce an approved internal registry or allowlist for third-party packages, preventing developers from pulling directly from public repositories without review.\n- Conduct regular security awareness training focused on supply chain risks, including how to verify package publishers and spot typosquatting.\n\n**Detection measures:**\n- Enable runtime behavioural monitoring on developer endpoints to detect anomalous command execution or data exfiltration originating from IDE processes.\n- Integrate dependency vulnerability alerts into SIEM dashboards to ensure security teams are notified of newly disclosed malicious packages in real time.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 2 – Inventory and Control of Software Assets","CIS Control 16 – Application Software Security","NIST SP 800-161 – Supply Chain Risk Management Practices","NIST SP 800-218 – Secure Software Development Framework (SSDF) PW.4","NIST CSF DE.CM-3 – Personnel activity monitoring","NIST CSF ID.SC-2 – Supplier and third-party risk identification","SLSA Framework – Supply chain Levels for Software Artifacts","OWASP Top 10: A06:2021 – Vulnerable and Outdated Components","ISO\u002FIEC 27036 – Information security for supplier relationships","GDPR Article 32 – Security of processing (where PII is exfiltrated)","published","2026-07-23T18:21:16.992893+00:00","2026-07-23T18:21:16.724+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fthreatsday-android-spyware-plc-attacks.html","threatsday-android-spyware-plc-attacks-ai-image-prompt-injection-12-more-stories-0fad97","ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":37,"name":38,"slug":39,"description":40,"color":41},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":43,"name":44,"slug":45,"description":46,"color":47},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]