feeds.feedburner.com • 6w
Multi-Vector Supply Chain Campaign: Mastra AI, GitHub Actions, and Arch Linux AUR Compromise
A sophisticated supply chain campaign, attributed to the suspected threat actor TeamPCP, has simultaneously targeted the Mastra AI framework via npm, GitHub Actions CI/CD workflows, and the Arch Linux User Repository (AUR). The attack utilized dormant contributor account takeovers to poison the @mastra npm scope using the easy-day-js dependency and hijacked GitHub Action version tags to exfiltrate CI/CD credentials. Additionally, over 1,500 AUR packages were compromised with eBPF-based rootkit malware. This coordinated infrastructure, linked by the "Mini Shai-Hulud" worm, facilitates widespread code execution, credential theft, and persistent rootkit deployment across development, DevOps, and end-user Linux environments.
Links:feeds.feedburner.com, Armorcode, Safestate, Bankinfosecurity, Security Affairs, cyberinsider.com, Infosecurity-magazine, techjacksolutions.com, arXiv (Computer Science - Cryptography and Security), Cybersecurity News, gbhackers.com, threat-modeling.com, appsec.fyi, Microsoft Security Blog, penligent.ai, DEV Community, Hexnode Blog, threatlocker.com, Labs, Privacyguides, Exchange, Resconinc, Reddit, Stepsecurity, bleepingcomputer.com, Daily, Callmissed, Kodaapi, Iipoman, Medium, Axipro, Securityweek, Foresiet, News4Hackers, Aiweekly, Thehackernews, Orca, Tenable Blog, falconinternet.net, datawater.com, thecyberexpress.com, Malware News, Crowdstrike, www.csoonline.com, Feedly, Blog, Datadoghq, Redcanary, Reversinglabs, Antiy, Securityboulevard, Hackread, Novee, Rootdata, Binance, App, Securityaffairs, Darkreading, Checkmarx, Techradar, Socprime, Balkanweb, Democrata, Kashmirlife, Inss, Promisedu, Dmarcreport, Strategicmarketresearch, Mdpi, Researchgate, Securereading, Securitymagazine, Eastmidlandscybersecure, Securityscorecard, Community, Safedep, Neuracybintel, Dark Reading •