v vanemmerik.ai / SUPPLY-CHAIN
Supply Chain · Watch Sunday · 16 August 2026 End-of-day synthesis 4 watches · 1 items

From the watchtower — what crossed the wire today.

A four-times-a-day standing watch on the open-source supply chain. Each pass pulls newly disclosed CVEs, freshly catalogued KEV adds, and active attacks reported in the wild — then ranks them by severity for the day.

The story of the day — A rare quiet day on the supply chain front — the only new signal was a macOS infostealer bolting live browser-session hijacking onto its ClickFix playbook.

No new supply-chain campaigns surfaced today. GHSA logged nothing in the last 26 hours, and none of the eighteen CISA KEV catalog entries added in the past 30 days are new — all were already triaged in prior editions of this watch.

The only fresh signal all day was AmnesiaStealer, a macOS infostealer riding the same ClickFix paste-and-run lure as its Windows and earlier macOS siblings. What's new is a streaming module that lets the operator interactively drive the victim's browser in real time, turning a one-shot credential grab into live session hijacking of cookies and authenticated SaaS tabs. It's not a package-registry compromise, but it's the same endgame most of this year's npm and PyPI campaigns have chased — steal the token, ride the session while it's still warm.

→ Operational priority for the night if you've already tuned detections for the ClickFix lure, confirm they also catch the new streaming C2 traffic and not just the initial drop; otherwise, it's a quiet night with no critical or high items to action.

13:00 ET · Forenoon Watch

AmnesiaStealer macOS malware adds a live remote-control module for hijacking browser sessions

AmnesiaStealer is a new macOS infostealer delivered via ClickFix lures that, beyond the usual credential and Keychain harvesting, ships a streaming module letting the operator interactively drive the victim's browser session in real time. That turns a one-shot credential grab into live session hijacking — cookies, saved logins, and any authenticated SaaS tab become directly usable by the attacker while the victim is still at the keyboard. Same ClickFix delivery chain as the Windows and prior macOS variants; if you've deployed detections for the paste-and-run lure, confirm they also catch the new streaming C2 traffic, not just the initial drop.