Collections

Supply Chain & Open-Source Security Collection

npm, PyPI, and other package-ecosystem compromises and dependency attacks.

2026-07-17 · MEDIUM

Published research article on IEEE about supply chain attacks and preventive security measures

2026-07-17 · MEDIUM

Is ast_grep_cli 0.44.1 on PyPI compromised? Windows Defender detected Trojan:Win64/Lazy!MTB during install

2026-07-15 · MEDIUM

​ ​AsyncAPI npm packages infected with credential-stealing malware

2026-07-14 · MEDIUM

AsyncAPI Supply Chain Compromise via GitHub Actions

2026-07-14 · MEDIUM

Multiple Jscrambler Packages Impacted by Supply Chain Attack

2026-07-13 · MEDIUM

Hackers backdoor Jscrambler npm package with infostealer malware

2026-07-13 · MEDIUM

Official jscrambler npm package compromised: malicious versions 8.14, 8.16, 8.17, and 8.20

2026-07-09 · MEDIUM

Injective SDK on npm infected with cryptocurrency wallet stealer

2026-07-08 · MEDIUM

Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials

2026-07-07 · MEDIUM

Safer-dependencies: A toolkit for claude code to ensure dependencies used aren't vuln, don't use abandoned packages, implement cooldown to avoid supply chain attacks, etc...

2026-07-06 · MEDIUM

North Korean Hackers Target Open Source Developers in Supply Chain Attacks