A supply chain attack campaign utilizing sleeper packages has been identified, distributing malicious payloads that enable credential theft, GitHub Actions tampering, and SSH persistence mechanisms. The attack is attributed to the GitHub account 'BufferZoneCorp' which has published malicious Ruby gems and Go modules.
30d signal volume
By Threat Layer
Top Signals
View all signals →Austrian police arrested a 39-year-old man suspected of poisoning baby food jars with rat poison in an extortion scheme. Five tampered HiPP brand jars were recovered across Austria, Czech Republic, and Slovakia before consumption, with one jar containing 15 micrograms of rat poison.