• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
Mobile menu toggle
  • Blog on X
  • Blog on Youtube
  • RSS feed X

Decipher Logo Home

  • Articles
  • Video
  • AI
  • Apple
  • General
  • Government
  • Intrusions
  • Law Enforcement
  • Microsoft
  • Open Source Software Security
  • Podcast
  • Supply Chain
  • Vulnerabilities
  • All Topics
  • Home
  • Articles
  • Video
  • Blog on X
  • Blog on Youtube
  • RSS feed X

All topics


Supply Chain


14 Posts

Ongoing Supply Chain Attack Expands to PyPi

Researchers have linked the compromise to the "Mini Shai-Hulud" campaign, which has been ongoing for several weeks and is associated with TeamPCP.

By Dennis Fisher

May 12, 2026 | 4 min read

Intrusionssupply chain

Attackers Target Checkmarx KICS Ecosystem

Yet another supply chain attack has hit the open source ecosystem, this time impacting the Checkmarx KICS Docker Hub repository.

By Lindsey O'Donnell-Welch

April 23, 2026 | 3 min read

Open sourcesupply chain

The Fallout From the Nasty Axios NPM Supply Chain Attack

Dennis and Lindsey dig into what we know do far about the supply chain attack on the axios NPM package, including how the attacker gained access to the maintainer’s account, the window of exposure for the malicious packages, the behavior of the RAT that’s installed on victims’ machines, and what the downstream effects may be.

By Dennis Fisher

April 1, 2026 | 1 min read

Video

Supply Chain Attack Hits Axios NPM Packages

Axios is a dependency in nearly 80% of all cloud and code environments and sees approximately 100 million downloads per week.

By Dennis Fisher

April 1, 2026 | 4 min read

Malwaresupply chain

TeamPCP’s Supply Chain Attack Spree Continues

TeamPCP’s latest victim is the Telnyx Python SDK on PyPl, coming after a wave of supply chain hits on Aqua Trivy, Checkmarx KICS/OpenVSX, and LiteLLM.

By Lindsey O'Donnell-Welch

March 27, 2026 | 3 min read

supply chainteampcp

Broad Exploit Activity Targets React2Shell Flaw

The vulnerability was disclosed publicly on Dec. 3 and researchers and threat intelligence teams immediately began seeing opportunistic and targeted exploitation attempts.

By Dennis Fisher

December 9, 2025 | 3 min read

ReactVulnerability
  • «
  • Page 1
  • Page 2
  • Page 3
  • »

sidebar

  • Blog on X
  • Blog on Youtube
  • RSS feed X
Home
  • Term & Conditions
  • ©2026 Decipher
  • Articles
  • Video

Powered by
Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
None
Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
None
Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
None
Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
None
Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
None
Powered by