Supply Chain Attacks
+ FollowSupply chain attacks indirectly infiltrate downstream users through open-source packages, development tools, CI/CD pipelines or trusted vendors. Recent incidents have centered on the NPM, PyPI and GitHub ecosystems, as well as AI development tools. North Korean hackers and groups including APT32 have also targeted cryptocurrency and fintech companies in attempts to steal credentials, wallet private keys and assets. Because malware can spread rapidly through updates and AI agent tools may expand the scope of execution, these risks warrant continued monitoring.
Key Moments
6 selectedThe full history is split into 6 equal periods by event count, taking the most-covered story from each. Coverage rises and falls with the news cycle, so sampling period by period keeps the most recent events from taking everything.
- 2026-08-21 Malicious ArrayRef Package Hits Solana and Ethereum Developers 3 reports
- 2026-07-07 North Korean Hackers Launch PolinRider Supply-Chain Attack to Steal Cryptocurrency 3 reports
- 2026-05-25 ‘TrapDoor’ Malware Targets Crypto and AI Development Tools in Supply-Chain Attack 4 reports
- 3 more key moments Sign up to see the full context
Event Timeline
31 core events17 peripheral mentions — events mainly about something else
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.