Supply-Chain Compromises

OWASP Agentic Top 10: ASI04 Agentic Supply Chain Vulnerabilities

Other agent threat types

Showing 41–60 of 60 threats, newest first

code-signingcertificate-theftsupply-chainGoldenEyeDogAPT-Q-27Dragon BreathDigiCertChina-nexusagent-relevant

A threat cluster dubbed CylindricalCanine, attributed as a sub-group of the Chinese cybercrime actor GoldenEyeDog (aka APT-Q-27, Dragon Breath, Miuuti Group), was linked to the April 2026 breach of certificate authority DigiCert and the theft of code-signing certificates. Stolen certificates can be used to sign malware so it appears trusted, enabling supply-chain compromise across downstream software consumers.

Updated Jul 19, 2026

npmsupply-chainblockchain-c2RATvitemalicious-packagesoftware-supply-chainagent-relevant

Researchers at Checkmarx identified seven malicious npm packages targeting the Vite frontend tooling ecosystem, codenamed ViteVenom, which deliver a remote access trojan (RAT). The campaign extends the previously observed ChainVeil operation, leveraging a four-tier blockchain-based command-and-control infrastructure spanning multiple chains including Tron to evade takedown and detection.

Updated Jul 18, 2026

MCPGitHub ActionsCI/CDRCEsecrets-exfiltrationpull-requestsupply-chainClaude CodeASI04 · Agentic Supply ChainAML.T0051AML.T0010Surface: Tool LayerPropagation: Single Hop

Claude Code Action, prior to version 1.0.74, checked out attacker-controlled pull request branches and blindly loaded and enabled any MCP servers defined in a PR's .mcp.json file. This allowed an external attacker to open a malicious pull request that, once processed by the Claude Code action, achieved arbitrary code execution on the GitHub Actions runner and exfiltrated CI secrets such as API keys and tokens.

Updated Jul 18, 2026

agent-skillsskill-marketplacesupply-chainlifecycle-securitysemantic-retrievalplanner-manipulationresearch-paperASI04 · Agentic Supply ChainSurface: Supply ChainPropagation: Single Hop

This is an academic research paper (arXiv, not an active exploit) introducing SkillSec-Eval, a framework for evaluating security risks across the full lifecycle of reusable LLM agent 'skills' — from repository admission through retrieval, planner selection, execution, and evolution. The authors evaluated 327 real-world skills and found vulnerabilities exist beyond just runtime execution, suggesting attackers could poison skills at earlier stages like publishing or ranking to influence which skills agents select and trust.

Updated Jul 16, 2026

githubinfostealermalwaresupply-chaintyposquattingsoftware-impersonationagent-relevant

A threat actor has created nearly 300 fake GitHub repositories impersonating legitimate software and security tools to distribute infostealer malware. Developers and security researchers searching for these tools risk downloading and executing malicious code disguised as trusted projects.

Updated Jul 15, 2026

data-poisoningscientific-integrityautonomous-agentsdataset-poisoningmisinformationresearch-agentsprovenanceLLM-agentsASI04 · Agentic Supply ChainAML.T0020AML.T0018AML.T0059Surface: Supply ChainPropagation: Single Hop

Researchers demonstrate that an adversary can poison an open dataset with misleading metadata and upload it to a public repository, causing autonomous AI research agents (built on Claude, GPT, Gemini) to unknowingly retrieve and use the poisoned data, producing fraudulent scientific conclusions in nearly half of tested runs. No prompt injection, agent compromise, or fabricated papers are needed — only manipulation of the open data ecosystem — and current agents rarely detect the poisoning (6% detection rate), though provenance auditing fully mitigates it in testing.

Updated Jul 14, 2026

npmsupply-chaininfostealerjscramblerjavascriptmalicious-packageagent-relevant

A threat actor compromised the Jscrambler npm package and published a malicious version containing infostealer malware, which was downloaded nearly 1,500 times before detection. This represents a supply chain attack targeting developers and CI/CD pipelines that depend on the Jscrambler client-side web security tooling.

Updated Jul 14, 2026

npmsupply-chaininfostealerrust-malwarepreinstall-hookagent-relevantjavascriptnodejs

The popular jscrambler npm package was compromised, with a malicious 8.14.0 release published on July 11, 2026 that executes a Rust-based infostealer via a preinstall hook during npm install. The attack drops platform-specific native binaries for Windows, macOS, and Linux, meaning any developer or CI/CD system installing this version is automatically compromised. Socket detected the malicious release within six minutes of publication, but organizations that auto-updated or pulled the package before detection remain at risk.

Updated Jul 12, 2026

supply-chainnpmcryptocurrencywallet-theftgithub-compromisemalicious-packageagent-relevant

Threat actors compromised the Injective Labs SDK GitHub repository and published a malicious version of the @injectivelabs/sdk-ts npm package embedded with fake telemetry code designed to steal cryptocurrency wallet private keys and mnemonic seed phrases. Developers and automated systems that installed the compromised version (1.20.21) are at risk of credential and asset theft.

Updated Jul 11, 2026 · CVSS 8.1

npmsupply-chainpackage-managerinstall-scripts2faagent-relevantdependency-securitynodejs

GitHub has released npm version 12, which disables automatic execution of package install scripts by default and deprecates granular access tokens (GATs) that could be used to bypass two-factor authentication. This is a defensive supply-chain security improvement aimed at reducing the risk of malicious packages executing arbitrary code during installation, a common vector in npm supply-chain attacks.

Updated Jul 10, 2026

npmsupply-chaincryptocurrencywallet-stealergithub-compromiseagent-relevant

Attackers compromised the GitHub repository of Injective Labs' SDK project and published a malicious version of the package to npm. The trojanized package harvested cryptocurrency wallet private keys and mnemonic seed phrases from developers and downstream applications that installed it.

Updated Jul 10, 2026

linuxopen-sourceinsider-threatdistributionrepository-securityagent-relevant

A contributor to the OpenMandriva Linux distribution reportedly attempted to sabotage the project following an internal dispute among maintainers. The distribution's team detected and responded to the incident, though specifics on the exact method and scope of the sabotage attempt remain limited in the initial reporting.

Updated Jul 10, 2026

hallucination-squattingpromptwareslopsquattingagentic-botnetremote-code-executiontool-executiontransferable-hallucinationsuntargeted-attackASI05 · Unsafe Code ExecutionAML.T0051AML.T0053AML.T0010Surface: Supply ChainPropagation: Self Propagating

Researchers demonstrate that LLM agents frequently hallucinate plausible-sounding resource names (repos, skills, packages) when performing tasks like cloning or installation, and these hallucinations are predictable and transferable across models. Attackers can preemptively register these hallucinated resource names to host malicious payloads, causing agents that autonomously fetch and execute them to become compromised at scale, effectively forming a botnet without needing any direct prompt injection channel.

Updated Jul 9, 2026

npmpypisupply-chaincredential-theftpayment-fraudstealer-malwaretyposquattingagent-relevant

Threat actors published malicious packages on npm and PyPI masquerading as legitimate SDKs for Paysafe, Skrill, and Neteller payment platforms. These packages deliver information-stealing malware that harvests credentials from developers and downstream application users. The campaign highlights the ongoing risk of typosquatting and impersonation attacks within open-source package registries.

Updated Jul 9, 2026

npmsupply-chainnorth-koreatyposquattingdeveloper-targetingcredential-theftagent-relevant

North Korea-linked threat actors published malicious npm packages ('rollup-packages-polyfill-core' and 'rollup-runtime-polyfill-core') that impersonate the legitimate 'rollup-plugin-polyfill-node' project, replicating its metadata to deceive developers. These packages are designed to enable remote access and exfiltrate developer secrets, continuing a pattern of North Korean supply-chain attacks against the JavaScript/npm ecosystem.

Updated Jul 6, 2026

supply-chainthird-party-skillsintegrity-verificationagent-securityvendor-reportASI04 · Agentic Supply ChainSurface: Supply ChainPropagation: None

This item is a vendor blog post from Unit 42 discussing general risks of integrating third-party 'skills' or plugins into enterprise AI agents, and advocating for integrity verification practices. It does not describe a specific vulnerability, exploit, or active threat, so it is classified as low severity informational content rather than a genuine incident.

Updated Jul 5, 2026

agent-marketplaceskill-poisoninginfostealeragentic-fraudscanner-evasionopenclawclawhubASI04 · Agentic Supply ChainAML.T0010AML.T0018AML.T0048Surface: Supply ChainPropagation: Single Hop

Unit 42 identified malicious 'skills' distributed through OpenClaw's ClawHub marketplace that evade automated security scanning to deploy infostealer malware and carry out agentic financial fraud. This represents a supply chain threat where trusted third-party agent extensions become a vector for compromising the host system and any credentials or financial capabilities the agent has access to.

Updated Jul 5, 2026

prompt-injectionunicode-tagsskillssupply-chainhidden-instructionsagent-backdoorgeminiclaudegrokASI04 · Agentic Supply ChainAML.T0051AML.T0043Surface: Supply ChainPropagation: Single Hop

A researcher demonstrated that AI 'Skills' (packaged capability bundles used by agent platforms) can be backdoored using invisible Unicode Tag codepoints that are stripped by human reviewers but still interpreted as instructions by models like Gemini, Claude, and Grok. This allows a malicious or compromised Skill to pass code review while silently injecting attacker instructions into the agent's context, enabling supply-chain prompt injection that survives manual auditing.

Updated Jul 5, 2026

north-koreasupply-chainnpmpackagistgolangchrome-extensioncontagious-interviewmaintainer-account-compromiseagent-relevant

North Korean threat actors tied to the Contagious Interview campaign have published 108 malicious packages and browser extensions across npm, Packagist, Go, and the Chrome Web Store in an operation dubbed PolinRider. The campaign leverages compromised maintainer accounts to distribute malware through widely trusted software registries, posing an ongoing supply-chain risk as new packages continue to surface.

Updated Jul 5, 2026

Supply ChainPythonDeveloper Tools

Coordinated campaign publishing typosquatted Python packages to steal environment variables, SSH keys, and cloud credentials from developer workstations and CI/CD pipelines.

Updated Jul 3, 2026