Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIBdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
A supply chain attack targeting WordPress plugin vendor BdThemes has been discovered, leading to temporary suspension of their plugin downloads. The attack uniquely manipulated JSON data rather than modifying source code in the official WordPress.org repository, allowing threat actors to create unauthorized administrator accounts.
AISolidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
Cybersecurity researchers have identified malicious Visual Studio Code extensions masquerading as Solidity development tools that steal cryptocurrency wallet credentials and API keys. The extensions, named 'solidity-pro' and distributed under different publisher names, targeted blockchain developers but have since been removed from the Open VSX marketplace.
AIQuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
Cybersecurity researchers at Fortinet FortiGuard Labs have uncovered a sustained supply chain attack targeting QuickFox, a VPN and network acceleration tool popular among overseas Chinese users. The attack, active since at least August 2025, distributes a trojanized Windows installer that delivers the FDMTP backdoor to compromise user systems.
AIHackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
Advertising technology company Adform suffered a supply chain attack on July 27, 2026, when threat actors compromised a JavaScript file to inject malicious code that replaced cryptocurrency wallet addresses in users' browsers. The attack affected multiple customer websites using Adform's services, potentially enabling attackers to redirect cryptocurrency transactions to attacker-controlled wallets
AIHackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts
A state-sponsored cyber campaign has compromised trusted South Korean websites to exploit vulnerabilities in AnySign4PC, a widely-used financial security software. The attackers leveraged these compromised sites to silently install SIGNBT or COPPERHEDGE backdoors on visitors' systems without user interaction or prompts, targeting users with vulnerable versions of the software.
AI144 Mastra npm Packages Compromised via Hijacked Contributor Account
A software supply chain attack codenamed 'easy-day-js' compromised 144 npm packages within the Mastra namespace, a popular framework for building AI applications. The attack was executed through a hijacked contributor account (ehindero) that mass-published malicious packages, posing significant risks to organizations using this JavaScript/TypeScript framework.
AIPopular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites
Attackers compromised JavaScript files used by three popular WordPress plugins (PushEngage, OptinMonster, and TrustPulse), injecting malicious code that created unauthorized admin accounts and installed hidden backdoor plugins when site administrators were logged in. The attack specifically targeted authenticated administrators while leaving ordinary site visitors unaffected, demonstrating a sophi
AIOver 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit
Over 400 packages in Arch Linux's Arch User Repository (AUR) were compromised this week through hijacked build scripts that deployed credential-stealing malware. The Rust-based infostealer targets developer secrets and can deploy an eBPF rootkit when executed with root privileges to evade detection.
AI400+ Arch Linux AUR Packages Hijacked to Install Rust Credential Stealer
Over 400 packages in Arch Linux's Arch User Repository (AUR) were compromised this week when attackers hijacked them and modified build scripts to deploy credential-stealing malware. The malicious payload is a Rust-based binary designed to harvest developer credentials and secrets, with the capability to deploy an eBPF rootkit when executed with root privileges to evade detection.
AIOceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack
The Vietnam-aligned threat actor OceanLotus has conducted two cyber espionage campaigns targeting Vietnamese infrastructure companies and stock investors using the SPECTRALVIPER backdoor. The attacks include a prolonged operation against a Vietnamese construction corporation spanning mid-2024 to February 2026, alongside a separate supply chain attack targeting investors.
AIMicrosoft Restores Some GitHub Repos, Keeps Others Offline as Miasma Probe Continues
Microsoft temporarily removed several GitHub repositories following a security incident that compromised 73 of its open-source projects with information-stealing malware. The company is conducting an ongoing investigation while prioritizing customer and ecosystem protection, with some repositories restored and others remaining offline during the probe.
AIDriveSurge Hijacks Thousands of Sites for ClickFix, FakeUpdate Attacks
DriveSurge, a large-scale initial access broker (IAB) operation, is leveraging a malicious traffic distribution system (TDS) to compromise thousands of legitimate websites. The campaign redirects unsuspecting visitors from trusted sites to malicious destinations that deploy ClickFix and FakeUpdate malware attacks, representing a significant supply chain security threat.
AIMiasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm
A supply chain attack dubbed Miasma has compromised Red Hat npm packages (@redhat-cloud-services) to deploy credential-stealing malware and a self-propagating worm on developer systems. The campaign employs Mini Shai-Hulud tactics including install-time execution, credential harvesting, CI/CD pipeline targeting, and encrypted data exfiltration. This incident represents a significant threat to ente
