Top stories.
- Major npm supply chain attack has been largely averted.
- ChillyHell malware targets macOS.
- US Treasury sanctions Southeast Asian scam networks.
- France warns of spyware campaign targeting Apple users.
- US warns of backdoored solar-powered highway infrastructure.
- Patch Tuesday notes.
Major npm supply chain attack has been largely averted.
Attackers launched a widespread supply chain attack earlier this week after hacking an npm developer's account, though the campaign wasn't as serious as some initial reports suggested, Infosecurity Magazine reports. Package maintainer Josh Junon confirmed that his npm account was compromised after he received a phishing email posing as a 2FA reset notification. The hackers then used Junon's "qix" npm account to publish malicious versions of dozens of packages Junon had maintained, which collectively receive more than 2.6 billion weekly downloads. The malicious code monitored the user's web browser for cryptocurrency addresses and replaced them with attacker-controlled addresses.
Less than four hours after Junon disclosed the hack, npm confirmed that all the malicious package versions had been shut down. Observers say the quick response highlighted the strength of the open-source security model. Arda Büyükkaya from EclecticIQ notes that npm recorded zero downloads of the malicious packages, and the attacker's cryptocurrency account currently has a balance of only sixty-six dollars.
ChillyHell malware targets macOS.
Jamf has published a report on a strain of macOS malware dubbed "ChillyHell" that's been active since 2021. The malware was first observed by Mandiant in a 2022 campaign targeting Ukrainian government officials. Jamf notes, "Between its multiple persistence mechanisms, ability to communicate over different protocols, and modular structure, ChillyHell is extraordinarily flexible. Capabilities such as timestomping and password cracking make this sample an unusual find in the current macOS threat landscape. Notably, ChillyHell was notarized and serves as an important reminder that not all malicious code comes unsigned."
US Treasury sanctions Southeast Asian scam networks.
The US Treasury Department has imposed sanctions on companies and individuals allegedly involved in large scam networks in Southeast Asia, Reuters reports. Treasury said the action "includes nine targets operating in Shwe Kokko, Burma, a notorious hub for virtual currency investment scams under the protection of the OFAC-designated Karen National Army (KNA), as well as ten targets based in Cambodia."
The scam compounds, particularly along the Thai-Myanmar border, are known for using forced labor and debt slavery to compel thousands of human-trafficking victims into carrying out online scams. The Treasury Department says these networks stole more than $10 billion from Americans last year.
France warns of spyware campaign targeting Apple users.
France's Computer Emergency Response Team (CERT-FR) issued an advisory this week regarding a spyware campaign targeting Apple users, Infosecurity Magazine reports. The advisory says Apple notified targeted users last week informing them that "at least one of the devices linked to [their] iCloud account has been targeted and is potentially compromised." Affected users will receive the alert via an email from Apple and as a notification in their iCloud account.
CERT-FR hasn't provided details on the campaign, but notes that popular spyware tools are often abused to target "journalists, lawyers, activists, politicians, senior officials, members of management committees in strategic sectors, etc."
US warns of backdoored solar-powered highway infrastructure.
Reuters reports that US officials have warned that solar-powered highway infrastructure, such as chargers, traffic cameras, and roadside weather stations, should be inspected for rogue devices hidden inside batteries and inverters. A private advisory issued last month by the US Department of Transportation's Federal Highway Administration said cellular radios had been discovered “in certain foreign-manufactured power inverters and [battery management systems]." The advisory didn't name any foreign countries, but Reuters notes that many of these devices are made in China.
Anomadarshi Barua, a researcher from George Mason University, told Reuters that such devices could be used to sabotage roadside infrastructure or disrupt traffic.
Patch Tuesday notes.
Microsoft this week issued patches for 81 vulnerabilities, including two publicly disclosed zero-day flaws, BleepingComputer reports. One of the zero-days (CVE-2025-55234) affects Windows SMB Server and could allow attackers to perform relay attacks and elevate privileges. The other zero-day (CVE-2024-21907) is a denial-of-service flaw that could be exploited by a remote, unauthenticated attacker. While these flaws were publicly known before patches were available, there's been no evidence of active exploitation.
The Register warns that SAP has fixed four critical flaws, including one with a CVSS score of 10. The maximum-severity vulnerability (CVE-2025-42944) affects SAP NetWeaver and can allow an unauthenticated attacker to "exploit the system through the RMI-P4 module by submitting [a] malicious payload to an open port." This "deserialization of such untrusted Java objects could lead to arbitrary OS command execution."
SecurityWeek notes that Adobe, Fortinet, Ivanti, and Nvidia released patches for high- and medium-severity vulnerabilities affecting their products. The publication also has a roundup of ICS patches, with fixes from Rockwell Automation, Siemens, Schneider Electric, and Phoenix Contact.