Urgent.News

the world's headlines, one feed

Editions

Tech

How open-source malware is re-targeting UK supply chains

Open-source malware has changed shape. What once focused on noisy cryptomining has moved toward something far more valuable: access.

How open-source malware is re-targeting UK supply chains

Open-source malware is evolving to focus on stealing credentials and secrets, rather than cryptomining. UK organizations are now specifically targeted. This marks a shift from opportunistic abuse to deliberate supply-chain compromise. Attackers aim for persistence and long-term access, which is harder to detect than resource abuse.

This shift in tactics demands a new security approach: securing dependencies and developer environments, not just runtime infrastructure. Modern malware often combines multiple threats, leading to multi-stage attacks with droppers, loaders, secret exfiltration features, and evolving post-installation behavior. As open-source usage grows, especially in JavaScript ecosystems, the risk surface expands significantly, with many applications depending on hundreds of direct and transitive packages.

This creates systemic exposure, making dependency governance a board-level concern. Automation in build systems can rapidly spread malware through compromised packages, bypassing runtime alerts. To combat this, security controls must be automated alongside automation, using real-time package intelligence and AI models grounded in authoritative, live ecosystem data.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.

Read the original at techradar.com →

More in Tech

DynamoDB: GSI, LSI, and related design ideas

This note explains the important DynamoDB concepts in a simple and practical way. First idea: think in access patterns Before designing a DynamoDB table, ask: What questions will the application ask?

Plan Around Next Month's Closure, Not Today's

Every traffic API on the market answers the same question: what is closed right now? That question is worth answering. It is also the wrong one for most of the decisions a planner actually makes.