<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
<url>
<loc>https://supplychainattack.org</loc>
<changefreq>daily</changefreq>
<priority>1</priority>
</url>
<url>
<loc>https://supplychainattack.org/stats</loc>
<changefreq>weekly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://supplychainattack.org/about</loc>
<changefreq>monthly</changefreq>
<priority>0.5</priority>
</url>
<url>
<loc>https://supplychainattack.org/contact</loc>
<changefreq>yearly</changefreq>
<priority>0.3</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/malware-in-doaction-types-tizsj5</loc>
<lastmod>2026-06-09</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/malware-in-doaction-eventemitter-l82ywq</loc>
<lastmod>2026-06-09</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/malware-in-doaction-http-6a47jx</loc>
<lastmod>2026-06-09</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/malware-in-doaction-pay-h76xyd</loc>
<lastmod>2026-06-09</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/malware-in-doaction-storage-k8m4uz</loc>
<lastmod>2026-06-09</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/malware-in-doaction-signalhub-17mzjx</loc>
<lastmod>2026-06-09</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/malware-in-doaction-wasm-loader-1r883x</loc>
<lastmod>2026-06-09</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/malware-in-clsx-js-v29yur</loc>
<lastmod>2026-06-09</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/malware-in-progerss-cli-1bk4x1</loc>
<lastmod>2026-06-09</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/malware-in-moustick-1sec7l</loc>
<lastmod>2026-06-09</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/malware-in-cookie-parser-legacy-pfpurb</loc>
<lastmod>2026-06-09</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/malware-in-github-archiver-186s6f</loc>
<lastmod>2026-06-09</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/malware-in-comos-sdk-15vzh4</loc>
<lastmod>2026-06-09</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/malware-in-buffer-utilities-hmqvb8</loc>
<lastmod>2026-06-09</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/malware-in-doaction-shared-17i56l</loc>
<lastmod>2026-06-09</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/malware-in-doaction-auth-d1ae9f</loc>
<lastmod>2026-06-09</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/malware-in-chai-mocks-bw7o1x</loc>
<lastmod>2026-06-08</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/the-hades-campaign-graph-ml-pypi-packages-deploy-cross-platform-memory-scrapers-1i5lk3</loc>
<lastmod>2026-06-08</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositorie-rl1iv8</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/miasma-npm-supply-chain-attack-self-spreading-worm-via-phantom-gyp-1b4n1o</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/new-ironworm-malware-hits-36-packages-in-npm-supply-chain-attack-12l3ww</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/hola-browser-for-windows-compromised-to-deliver-cryptominer-1smv3g</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/multiple-redhat-cloud-services-npm-packages-compromised-1gtdw3</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/miasma-supply-chain-attack-targeting-redhat-npm-packages-1kq1ng</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/laravel-lang-supply-chain-attack-every-tag-across-multiple-composer-packages-rew-h0akan</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/microsoft-s-durabletask-pypi-package-compromised-in-supply-chain-attack-vomlz6</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/the-worm-that-keeps-on-digging-teampcp-hits-antv-in-latest-wave-1lm5r0</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/durabletask-teampcp-s-latest-pypi-compromise-84w43k</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/active-supply-chain-attack-malicious-node-ipc-versions-published-to-npm-kldfl8</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/shai-hulud-here-we-go-again-mass-npm-supply-chain-attack-hits-the-antv-ecosystem-1kfeld</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/teampcp-s-mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-compromis-19lamt</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised-19yya2</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/bitwarden-cli-hijacked-on-npm-bun-staged-credential-stealer-targets-developers-g-n1hhgh</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/a-mini-shai-hulud-has-appeared-obfuscated-bun-runtime-payloads-hit-sap-related-n-1ec9xf</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/teampcp-injects-two-stage-credential-stealer-into-xinference-pypi-package-1du39z</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/shai-hulud-worm-pivots-to-multi-cloud-intercom-client-7-0-4-hijacked-361-000-wee-5p9im6</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/lightning-obfuscated-javascript-credential-stealer-bundled-in-pypi-wheel-1h10or</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/supply-chain-campaign-targets-sap-npm-packages-with-credential-stealing-malware-1ghzqn</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/context-ai-oauth-token-compromise-1h8o51</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/behind-the-scenes-how-stepsecurity-detected-and-helped-remediate-the-largest-npm-1fmmcy</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/cline-supply-chain-attack-detected-cline-2-3-0-silently-installs-openclaw-fw2a0t</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan-1py3ac</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/velora-dex-sdk-compromised-on-npm-malicious-version-drops-macos-backdoor-via-lau-10jrzk</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/10-layers-deep-how-stepsecurity-stops-teampcp-s-trivy-supply-chain-attack-on-git-1gzwzb</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/six-accounts-one-actor-inside-the-prt-scan-supply-chain-campaign-1s2s4f</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/malicious-iolitelabs-vscode-extensions-target-solidity-developers-on-windows-mac-1fkfap</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/axios-npm-distribution-compromised-in-supply-chain-attack-81wu4e</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/teampcp-plants-wav-steganography-credential-stealer-in-telnyx-pypi-package-iwek9d</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/litellm-credential-stealer-hidden-in-pypi-wheel-ythjti</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/kics-github-action-compromised-teampcp-strikes-again-in-supply-chain-attack-1jcbe8</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/trivy-compromised-everything-you-need-to-know-about-the-latest-supply-chain-atta-103yjm</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/bittensor-wallet-4-0-2-compromised-on-pypi-backdoor-exfiltrates-private-keys-2b196w</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/malicious-npm-releases-found-in-popular-react-native-packages-130k-monthly-downl-54qovl</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/incident/xygeni-action-compromised-c2-reverse-shell-backdoor-injected-via-tag-poisoning-xeslq4</loc>
<lastmod>2026-06-07</lastmod>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://supplychainattack.org/ecosystem/npm</loc>
<changefreq>monthly</changefreq>
<priority>0.4</priority>
</url>
<url>
<loc>https://supplychainattack.org/ecosystem/pypi</loc>
<changefreq>monthly</changefreq>
<priority>0.4</priority>
</url>
<url>
<loc>https://supplychainattack.org/ecosystem/ai-agents</loc>
<changefreq>monthly</changefreq>
<priority>0.4</priority>
</url>
<url>
<loc>https://supplychainattack.org/ecosystem/other</loc>
<changefreq>monthly</changefreq>
<priority>0.4</priority>
</url>
<url>
<loc>https://supplychainattack.org/ecosystem/container-registry</loc>
<changefreq>monthly</changefreq>
<priority>0.4</priority>
</url>
<url>
<loc>https://supplychainattack.org/vector/compromised-package</loc>
<changefreq>monthly</changefreq>
<priority>0.4</priority>
</url>
<url>
<loc>https://supplychainattack.org/vector/malicious-commit</loc>
<changefreq>monthly</changefreq>
<priority>0.4</priority>
</url>
<url>
<loc>https://supplychainattack.org/vector/account-takeover</loc>
<changefreq>monthly</changefreq>
<priority>0.4</priority>
</url>
<url>
<loc>https://supplychainattack.org/vector/update-server-compromise</loc>
<changefreq>monthly</changefreq>
<priority>0.4</priority>
</url>
<url>
<loc>https://supplychainattack.org/vector/malicious-maintainer</loc>
<changefreq>monthly</changefreq>
<priority>0.4</priority>
</url>
<url>
<loc>https://supplychainattack.org/vector/build-system-compromise</loc>
<changefreq>monthly</changefreq>
<priority>0.4</priority>
</url>
<url>
<loc>https://supplychainattack.org/vector/third-party-vendor-breach</loc>
<changefreq>monthly</changefreq>
<priority>0.4</priority>
</url>
</urlset>
