2026-10-11 17:10 UTC

supply-chain-security

band: hotmomentum: stable score: 0.942
temperature history

Episodes (15)

Independent testing will determine whether Augur reliably detects and removes hidden characters, watermarks, prompt-injection payloads, and other embedded content from agent skills and data files.
expiredknownscott: low
Independent verification and platform response will determine whether an Anthropic-hosted, Google-ranked Claude artifact impersonated Claude Code installation guidance and delivered a macOS infostealer.
expiredknownscott: medium
Happy Fellow’s analysis claims Omarchy’s development and release practices predictably introduce security weaknesses that require stronger software-supply-chain controls.
expiredknownscott: low
OpenCode’s maintainers disclose that GHSA-pffc-58xr-hggc is a security vulnerability requiring remediation to protect coding-agent users and projects from compromise.
expiredknownscott: medium
BleepingComputer reports that more than 8,300 internet-exposed Gitea servers are vulnerable to code-execution attacks, creating an urgent patching and exposure-reduction event for self-hosted source control.
expirednovelscott: low
The authors of “Trusting-Trust Attack against an Entire Linux Distribution” claim a distribution-wide trusting-trust attack, potentially showing that inspecting source alone cannot establish the integrity of a Linux software supply chain.
expiredknownscott: low
Tripwire creator neomatrix369 presents its released repository as a sandboxed security scanner for AI skills and MCP servers, potentially providing a pre-deployment inspection control for third-party agent components.
resolvedknownscott: low
SkillProof claims its published adversarial tests fail four of five pinned official MCP server versions, including SSRF, read-only transaction escape, and arbitrary file-write findings, potentially requiring stronger deployment boundaries than official provenance alone provides.
corroboratedconvergesscott: medium
Kenwea claims its released Notary tooling executes a package's own install surface under constrained sandbox conditions and signs hash-bound results, enabling verifiable pre-install and CI checks without certifying package safety or transitive dependencies.
seedknownscott: low
Hacktron claims its HEIF Heist investigation found native image-decoder vulnerabilities enabling data exposure or remote code execution across major services and frameworks, making transitive decoder patching and image-processing isolation material production-security requirements.
resolvedknownscott: low
Security reporter 6mile alleges two open shadcn/ui pull requests contain executable PolinRider payloads appended to build configurations, creating a maintainer-compromise risk before merge as well as a potential downstream supply-chain threat.
seedconvergesscott: high
Rust's Security Response Team reports that Miri persists environment secrets into cached target directories readable by GitHub pull-request workflows, requiring affected projects to clear caches and restrict secret exposure despite the forthcoming Miri fix.
resolvedknownscott: low
Arusekk's disclosure shows a wormable account-takeover XSS (CVE-2026-92973) in ansi2html's OSC 8 hyperlink handling, establishing rendering of attacker-controlled build, CI, or agent terminal output as HTML as an account-takeover class for any trusted UI — agent-log viewers included — absent sanitization or CSP.
resolvedconvergesscott: high
Socket reports that GitHub's September 16 re-enablement of two compromised actions-cool GitHub Actions — with their May 2026 Mini Shai-Hulud malicious tags never cleaned — reactivated payload execution across thousands of repositories referencing them by tag, and the cleanup and platform response will establish how GitHub remediates re-enabled compromised repositories.
watchingconvergesscott: high
The GhostAction supply-chain campaign escalates by registering lookalike domains my-github.com and my-gitlab.com that resolve to attacker infrastructure, enabling phishing, malicious clone URLs, token theft, and CI/CD secret collection — a shift from IP-based collectors to developer-familiar domains for credential harvesting and workflow injection.
corroboratednovelscott: high

Trajectory notes