Supply-Chain Compromises

Malicious packages, hijacked maintainer accounts, tampered installers, and compromised registries — attacks that arrive through the software you deliberately installed. For AI agents the supply chain also includes models, system prompts, skills, and MCP tool servers pulled from public registries (OWASP ASI04); compromise any of them and every agent that installs it is compromised.

OWASP Agentic Top 10: ASI04 Agentic Supply Chain Vulnerabilities

Other agent threat types

Showing 1–20 of 60 threats, newest first

supply-chainterraformcloudflarecredential-theftregistry-compromiseiacagent-relevant

Attackers gained unauthorized access to Coder's Cloudflare-hosted registry infrastructure and inserted rogue registry servers distributing trojanized Terraform modules. These malicious modules contained credential-stealing code, potentially exposing secrets and cloud credentials for any environment that pulled infrastructure definitions from the compromised registry.

Updated Sep 4, 2026

model-provenancebackbone-substitutionauditresearchtool-use-fingerprintingapi-integrityASI09 · Human Trust ExploitationSurface: Supply ChainPropagation: None

This is an academic research paper describing a defensive auditing technique, not an active threat or exploit. AgentProv helps detect when commercial LLM API providers silently swap, quantize, or wrap the advertised model, using tool-call patterns instead of unreliable text-output analysis. It is a beneficial transparency/integrity tool for consumers of agentic LLM APIs, not an attack vector.

Updated Sep 2, 2026

supply-chainpackagistcomposerphpiosspywaread-fraudmobilemalicious-packagesoftware-composition

Researchers discovered 13 malicious Composer theme packages on Packagist designed to inject JavaScript into Vietnamese movie and comic streaming sites. The injected code performs mobile ad-fraud and gambling-redirect operations and deploys spyware targeting unpatched iOS devices visiting the compromised sites.

Updated Sep 2, 2026

iam-misconfigurationoidcawsgithub-actionssupply-chaincicd-securityagent-relevant

A critical flaw in @hulumi/policies before version 1.3.2 allows attackers to craft AWS IAM condition operators (ForAnyValue:StringLike) that evade security guardrails designed to detect overly permissive GitHub Actions OIDC trust policies. This enables attackers to establish stealthy, wildcard-based trust relationships between arbitrary GitHub repositories/workflows and AWS IAM roles, potentially leading to unauthorized cross-account access.

Updated Sep 1, 2026 · CVSS 9.8

path-traversalzip-extractionmcpbmcp-server-managementarbitrary-file-writearbitrary-file-deletemanifest-injectionASI04 · Agentic Supply ChainSurface: Tool LayerPropagation: Single Hop

MCPHub, a hub for managing multiple MCP servers, fails to sanitize the manifest.json 'name' field when extracting uploaded MCPB (zip) files, allowing an attacker to use path traversal sequences to write files outside the intended extraction directory. The same unsanitized field is also used during cleanup, enabling arbitrary directory deletion. This lets a malicious MCP server package achieve file system compromise on the host running MCPHub, potentially leading to code execution or destructive data loss.

Updated Sep 1, 2026

browser-extensioncryptocurrency-theftmalicious-extensionchromeedgewallet-stealeragent-relevant

Researchers identified 19 malicious Chrome and Edge extensions published over the past six months that steal cryptocurrency wallet secrets and drain funds. The extensions share common code and tradecraft, suggesting a coordinated campaign distributed through official browser extension stores. This poses a broad supply-chain risk to any user or organization installing these extensions.

Updated Aug 31, 2026

browser-extensionchrome-web-storeedgecryptocurrency-theftclickfixmalware-frameworkdata-exfiltrationagent-relevant

Multiple malicious extensions distributed through the Chrome Web Store and Microsoft Edge Add-ons store delivered a modular malware framework capable of stealing cryptocurrency, browsing history, and other sensitive data. The campaign also deployed ClickFix-style social engineering lures to trick users into executing further malicious commands, expanding the attack's reach beyond simple browser compromise.

Updated Aug 31, 2026

supply-chain-attackopen-sourcenpmmalicious-packagescybercrimeextortionarrestlaw-enforcementagent-relevant

Australian Federal Police arrested two suspects believed to be members of TeamPCP, a cybercrime group linked to what is described as the longest-running spree of software supply chain attacks via malicious open-source packages. The group allegedly compromised thousands of global businesses by distributing trojanized open-source software components. While this report covers the law enforcement action, the underlying threat—malicious open-source packages—remains a systemic risk to any organization consuming public package repositories.

Updated Aug 28, 2026

nokogirirubylibxml2libxsltxml-parsingdenial-of-servicememory-disclosurercesupply-chainagent-relevant

Nokogiri versions before 1.13.2 for CRuby ship vulnerable vendored copies of libxml2 2.9.12 and libxslt 1.1.34, exposing applications to denial-of-service, memory disclosure, and potential remote code execution when processing untrusted XML/XSL input. This is a widely-used Ruby gem for XML/HTML parsing, meaning the vulnerability propagates transitively into any application, service, or pipeline that depends on it.

Updated Aug 26, 2026 · CVSS 9.8

gitpythonpythonsupply-chainrcegit-config-injectionagent-relevantci-cddependency-risk

GitPython versions before 3.1.59 mishandle multi-line git-config values during write operations, allowing crafted config entries with embedded newlines to be corrupted into live directives such as core.hooksPath. This enables an attacker who can influence a repository's config file to achieve arbitrary code execution the next time any unrelated GitPython write operation touches that config, with a critical CVSS score of 9.8.

Updated Aug 26, 2026 · CVSS 9.8

prototype-pollutionnodejsnpmsupply-chainexceljsagent-relevantRAGjson-parsing

A critical prototype pollution vulnerability exists in exceljs-hardened versions prior to 5.0.0, where the deepMerge helper fails to sanitize dangerous keys (__proto__, constructor, prototype) when merging cell note objects. Attackers can craft malicious spreadsheet or JSON input to pollute Object.prototype, potentially leading to remote code execution, denial of service, or security bypass in downstream application logic.

Updated Aug 24, 2026 · CVSS 9.4

androidiotbotnetproxy-abusead-fraudsupply-chainautomotivemalware

Attackers compromised a legitimate Android device-update application distributed with car head units, using it to deliver malware that enrolls devices into a proxy botnet and conducts ad fraud. This supply-chain compromise leverages a trusted update mechanism to gain persistent access to a large, distributed fleet of embedded automotive devices.

Updated Aug 23, 2026

npmsupply-chainlinuxbackdoormalicious-packageai-c2agent-relevantnodejsdeveloper-tools

Researchers identified 14 trojanized npm packages disguised as calendar and streak-tracking utilities that covertly deploy an AI-powered Linux backdoor called RedC2 4.0. The malware extracts and executes a bundled binary as a detached background process, giving attackers persistent, AI-assisted command-and-control capability on infected hosts.

Updated Aug 22, 2026

supply-chainrustcrates.iobuild-time-malwaredependency-confusiontyposquattingagent-relevant

A compromised maintainer account was used to publish malicious versions of three popular Rust crates (arrayref, internment, append-only-vec), collectively downloaded over 245 million times. The malicious releases introduced a typosquatted dependency whose build script downloaded and executed a remote payload at compile time, enabling arbitrary code execution on any system that built the affected packages.

Updated Aug 21, 2026

supply-chainrustcrates.ioinfostealermalicious-packagebuild-time-executionagent-relevant

Attackers compromised the maintainer account of the widely-used Rust crate 'arrayref' and published a malicious version that executes infostealer malware at compile time on developer systems. Any developer or CI/CD pipeline pulling the poisoned version would trigger malware execution during the build process, risking credential and secret theft.

Updated Aug 21, 2026

github-actionsworkflow-injectionci-cdsupply-chaincredential-theftsnowflakeagent-relevant

Researchers at Wiz disclosed a GitHub Actions workflow injection vulnerability in Snowflake's public snowflake-connector-net repository, where a maliciously crafted GitHub issue could trigger command injection in a workflow that contained internal Jira credentials. Successful exploitation could allow an attacker to exfiltrate secrets and potentially compromise the CI/CD pipeline of a widely used Snowflake connector library.

Updated Aug 18, 2026

supply-chainpypilitellmcredential-theftpythonagent-relevantcloud-securitysecrets-exposure

Two malicious versions of the popular LiteLLM package were published to PyPI in March and remained live for roughly 40 minutes, long enough to be pulled by automated build pipelines and developers. The packages contained credential-harvesting code that exfiltrated cloud keys, SSH keys, Kubernetes tokens, and database passwords, with CloudSEK estimating exposure impacting over 2,100 organizations based on a dataset of ~434,000 captured files.

Updated Aug 15, 2026

wordpressplugin-backdoorsupply-chainrcepersistenceweb-shell

A tampered build of Ninja Tables Pro 5.2.11 was distributed through a decommissioned update server, embedding a malicious PHP updater component that grants attackers persistent backdoor access. The compromised plugin creates a passwordless admin account, drops web shells in mu-plugins and uploads directories, and registers scheduled tasks that survive plugin removal, making remediation difficult. Organizations running affected WordPress instances face full site takeover risk, including any hosted applications, APIs, or backend services running on the same host.

Updated Aug 14, 2026 · CVSS 9.8

wordpresssupply-chainbackdoorplugin-compromiseagent-relevantpersistencerce

A tampered build of Fluent Forms Pro 6.2.7 distributed via a decommissioned update server injects a malicious PHP file that installs a backdoor REST API endpoint, a passwordless administrator account, and persistent scheduled tasks. This constitutes a supply-chain compromise capable of full site takeover, with persistence mechanisms designed to survive plugin removal.

Updated Aug 14, 2026 · CVSS 9.8

agent-skillsstatic-analysisresearchprompt-injectionhost-destructionskill-packagesLLM-agentsdetection-gapASI04 · Agentic Supply ChainAML.T0010AML.T0051AML.T0053Surface: Supply ChainPropagation: Single Hop

This is a research paper (not an active exploit) that benchmarks static analysis techniques against malicious 'Agent Skills' — installable instruction/script packages for LLM agents. The authors show static analysis catches data exfiltration and steganographic payloads well but completely misses host-destruction attacks using common shell commands and largely misses natural-language prompt injection, highlighting a real supply-chain detection gap for agent skill marketplaces.

Updated Aug 11, 2026