3 articles · Curated and written by practitioners

19 Chrome, Edge Extensions Found Stealing Crypto Wallets, Data
Socket researchers uncovered 19 Chrome and Edge extensions, 14 built by attackers, five acquired from legitimate developers, running a modular framework that drains crypto wallets, harvests exchange sessions, and steals credentials since as early as February 2024.

Over 400 Arch Linux AUR Packages Hijacked in 'Atomic Arch' Supply-Chain Attack
Attackers adopted orphaned Arch User Repository packages and rewrote their build scripts to pull a malicious npm dependency (atomic-lockfile), delivering a Rust credential stealer with an optional root-only eBPF rootkit. Arch's official repositories were not affected.

Cisco Source Code Stolen in Trivy Supply-Chain Breach, BleepingComputer Reports
Threat actors used credentials harvested in the TeamPCP Trivy supply-chain compromise (CVE-2026-33634) to breach Cisco's development environment, cloning 300+ GitHub repositories - including AI Assistant and AI Defense source code - and accessing a small number of AWS accounts, according to BleepingComputer.

