logo

November 2024 in Software Supply Chain Security

ID: 3ac965a1-4b47-5926-8b20-b01e565dd3b4

STIX ID: report--3ac965a1-4b47-5926-8b20-b01e565dd3b4

Feed Name: Checkmarx Zero

Threat Score
72/100

Date Published: 2024-12-10

Date Updated: 2026-04-27

Author: Yehuda Gelb

...
...

In November 2024 supply-chain attacks highlighted attackers' 'legitimate-first' package strategies and creative abuse of official documentation: a year-long malicious NPM package combined crypto-mining and data theft affecting dozens of systems, an NPM package mirrored a React Native documentation example to trick developers, and the aiocpa PyPI package was weaponized to steal cryptocurrency credentials via Telegram after months of legitimate use; the report also notes improvements against StarJacking in some repositories but warns that the risk remains and urges continued vigilance in package verification and ecosystem defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.