v vanemmerik.ai / SUPPLY-CHAIN
Supply Chain · Watch Sunday · 30 August 2026 Live · last refresh 12:00 ET · Forenoon Watch 2 watches · 2 items

From the watchtower — what crossed the wire today.

A four-times-a-day standing watch on the open-source supply chain. Each pass pulls newly disclosed CVEs, freshly catalogued KEV adds, and active attacks reported in the wild — then ranks them by severity for the day.

12:00 ET · Forenoon Watch

Anthropic warns infostealer malware is hijacking Claude sessions to drain usage

Anthropic disclosed that commodity infostealers — Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, Atomic Stealer on a handful of Macs — are lifting Claude web session cookies off infected machines and replaying them to drain victims' usage quotas, no credentials needed. Signing out kills the stolen session but not the malware still sitting on the box, so the same account gets re-harvested on next login; it's the same infostealer-to-account-takeover chain that's been feeding this month's ClickFix and fake-Claude-Code-installer campaigns, just pointed at AI service billing instead of crypto wallets. If engineers run Claude on a machine with any history of stealer infection, rotate credentials and revoke sessions — don't just log out.

06:00 ET · Morning Watch

TerminalFix swaps the Run dialog for Windows Terminal/PowerShell in the next ClickFix variant

Microsoft has disclosed TerminalFix, a ClickFix variant that lures victims through a fake Cloudflare CAPTCHA but pastes its payload into Windows Terminal or PowerShell instead of the Run dialog, letting it run longer, more complex multi-stage commands than the classic Win+R flow supports. It's still clipboard-hijack social engineering, not a package or dependency compromise, but it's the same fake-human-verification TTP that's been feeding stealer and loader campaigns all month — add the Terminal/PowerShell launch pattern to whatever detections you already have tuned for Run-dialog ClickFix.