ALERT

ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know      ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know

Home/The Wire/2026-04-05
▶The Wire — Daily Briefing

The Wire — Sunday, April 5, 2026

When Everything Developers Touch Becomes a Weapon

7 stories analyzed

When Everything Developers Touch Becomes a Weapon

The security landscape over the past 24 hours reveals a chilling convergence: attackers are systematically targeting the tools, accounts, and supply chains that developers depend on, understanding that a single compromised library or trusted application can cascade into thousands of breached organizations. From npm registries to government commission networks, the pattern is unmistakable—and it's accelerating.

The most alarming story emerging today is the scale of supply chain compromise we're now treating as routine. The Axios npm hack used fake Teams error fix to hijack maintainer account reveals a sophisticated operation that went beyond technical exploitation. North Korean threat actors reportedly targeted a developer with a social engineering campaign designed specifically to steal credentials for a widely-trusted HTTP client library. That's not a breakthrough in some obscure security tool—Axios is downloaded millions of times monthly. One compromised maintainer account could have poisoned dependency trees across the entire developer ecosystem. The fact that this attack succeeded at all, and that the post-mortem is still being published, suggests these actors understand developer psychology and infrastructure better than we'd like to admit.

This same pattern repeated itself across the npm ecosystem at scale. Researchers discovered 36 malicious npm packages exploited Redis, PostgreSQL to deploy persistent implants, each disguised as legitimate Strapi CMS plugins. These weren't one-off proof-of-concept attacks. The packages included functionality to harvest credentials, establish reverse shells, and drop persistent backdoors. Every package on that list could have infected production environments—and the researchers don't know how many installations occurred before detection. The npm registry has become a primary attack surface, and trust is increasingly the only thing separating legitimate packages from sabotaged ones.

The European Commission learned this lesson the hard way. European Commission Confirms Data Breach Linked to Trivy Supply Chain Attack represents one of the most significant supply chain breaches of the quarter. Over 300GB of data was stolen from the Commission's AWS environment, including personal information, after attackers compromised what should have been a trusted vulnerability scanner. A tool designed to protect infrastructure became the vector through which attackers breached a critical EU institution. The implications go beyond data loss—they raise fundamental questions about how we validate the integrity of the tools we use to secure our own systems.

At the infrastructure level, the urgency is equally acute. Fortinet patches actively exploited CVE-2026-35616 in FortiClient EMS represents a critical vulnerability (CVSS 9.1) that has already been weaponized in the wild. A pre-authentication API bypass in endpoint management systems is precisely the kind of flaw that gives attackers foot-in-the-door access to entire corporate networks. Fortinet's out-of-band patch release signals that this isn't theoretical—attacks are already underway. Organizations running FortiClient EMS without these patches are almost certainly compromised.

But the attack surface extends far beyond traditional vulnerabilities. Attackers are increasingly exploiting the trust we place in everyday browser applications and authentication mechanisms. LinkedIn secretly scans for 6,000+ Chrome extensions, collects data surfaced a troubling privacy violation, but it also highlights how surveillance has become baked into platforms we use without thinking. The discovery of hidden JavaScript scanning visitor browsers for extensions reveals a creeping normalization of invasive data collection practices. When legitimate platforms can't be trusted to respect user privacy, attackers find fertile ground for their own surveillance and tracking.

Meanwhile, a different class of attacker is weaponizing OAuth itself. Device code phishing attacks surge 37x as new kits spread online shows that account compromise techniques continue to evolve faster than user awareness. A 37x surge in device code phishing in just weeks, with attack kits now openly distributed, suggests that this vector has crossed from novel technique to commodity attack. This is OAuth 2.0 Device Authorization Grant abuse scaled to masses—and the fact that kits are spreading online means we should expect this trend to worsen before it improves.

Our analysis shows three interconnected threats crystallizing simultaneously. First, supply chain attacks are no longer rare compromises of obscure tools—they're targeting the most critical and widely-trusted libraries and platforms in the software ecosystem. Second, the velocity of exploitation is accelerating; vulnerabilities like Fortinet's are being weaponized within hours. Third, attackers are diversifying their approach, combining social engineering, infrastructure exploits, and account-takeover techniques to maximize impact. A single developer targeted with a fake Teams notification can poison thousands of downstream projects. A single vulnerability in a widely-installed endpoint management system can breach entire enterprises. A novel OAuth attack vector can become a commodity assault within weeks.

The common thread is trust. Developers trust the packages they import. Organizations trust their endpoint security tools. Users trust their browsers and the services they use daily. Attackers have become expert at weaponizing that trust—compromising the most trusted tools and platforms precisely because they're so widely deployed and so deeply embedded in business-critical infrastructure.

What security professionals should pay attention to today isn't just the individual stories—it's the pattern they form. The question isn't whether your supply chain has been compromised; it's whether you'd know if it had. Patch Fortinet immediately. Audit your npm dependencies for recent modifications. Assume your OAuth flows are under active attack. And most critically: validate the integrity of the tools you trust most, because attackers certainly will.

The next 48 hours will tell us whether these are isolated incidents or the beginning of a coordinated campaign. We're watching.

Key Takeaways

  • Supply chain attacks are now hitting flagship projects: Axios, npm packages, and government infrastructure represent a shift toward targeting the tools developers rely on most—assume your dependencies are under active scrutiny
  • Patch Fortinet immediately: CVE-2026-35616 is actively exploited with a 9.1 CVSS score; an unpatched FortiClient EMS is a direct entry point for attackers
  • Device code phishing is becoming a commodity attack: A 37x surge in OAuth abuse attacks with freely available toolkits means account compromise is about to become endemic—enforce MFA and monitor for anomalous OAuth flows
  • Trust is now the primary vulnerability: LinkedIn's hidden extension scanning, social engineering campaigns, and widespread malicious packages show that we need verification mechanisms beyond trust—validate tools, audit dependencies, and assume infrastructure tools have been compromised

The Wire is HackWire's daily editorial briefing, published every morning.