Collections
Supply Chain & Open-Source Security Collection
npm, PyPI, and other package-ecosystem compromises and dependency attacks.
2026-07-17 · MEDIUM
Published research article on IEEE about supply chain attacks and preventive security measures
2026-07-17 · MEDIUM
Is ast_grep_cli 0.44.1 on PyPI compromised? Windows Defender detected Trojan:Win64/Lazy!MTB during install
2026-07-15 · MEDIUM
AsyncAPI npm packages infected with credential-stealing malware
2026-07-14 · MEDIUM
AsyncAPI Supply Chain Compromise via GitHub Actions
2026-07-14 · MEDIUM
Multiple Jscrambler Packages Impacted by Supply Chain Attack
2026-07-13 · MEDIUM
Hackers backdoor Jscrambler npm package with infostealer malware
2026-07-13 · MEDIUM
Official jscrambler npm package compromised: malicious versions 8.14, 8.16, 8.17, and 8.20
2026-07-09 · MEDIUM
Injective SDK on npm infected with cryptocurrency wallet stealer
2026-07-08 · MEDIUM
Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials
2026-07-07 · MEDIUM
Safer-dependencies: A toolkit for claude code to ensure dependencies used aren't vuln, don't use abandoned packages, implement cooldown to avoid supply chain attacks, etc...
2026-07-06 · MEDIUM
North Korean Hackers Target Open Source Developers in Supply Chain Attacks