13 stories tagged with #supply-chain-attacks, in publish-time order across the WeSearch catalog. Tag pages update as new stories ingest.
⌘ RSS feed for this tag → or search "Supply Chain Attacks"
A practical checklist for evaluating npm packages (supply chain attacks, slopsquatting, etc.)
Prevent supply chain attacks
Prevent supply chain attacks
CrowdStrike and Google take down botnet used by hackers to target software developers in supply chain attacks
Cybercriminals used the Glassworm botnet to infect open source software projects with malware, and in turn hack the developers and companies that use that software.…
Supply Chain Attacks Cluster: 230K Advisories, Five Patterns
Pulled the full OSV mirror for npm and PyPI — 230,000+ advisories. The malicious-tagged subset clusters into five recurring patterns. None of them are clever. All of them keep work…
The Three-Body Problem: AI Code, Supply Chain Attacks, and the Talent Exodus
In physics, the three-body problem describes a system where three objects interact gravitationally in...…
Supply Chain Attacks + Stale Credentials: Why This Combination Is So Dangerous in 2026
Recent incidents at GitHub and Grafana Labs highlight a painful truth in modern infrastructure: even...…
Supply chain attacks and OSS sustainability go hand in hand
Supply chain attacks and OSS sustainability go hand in hand. I've semi-seriously joked for years that OSS upstreams should periodically purposely inject full vulns into their code …
Socket: TeamPCP, the gang claiming GitHub's repositories breach, also executed 20 "waves" of supply chain attacks recently, compromising 500+ pieces of software (Wired)
Wired : Socket: TeamPCP, the gang claiming GitHub's repositories breach, also executed 20 “waves” of supply chain attacks recently, compromising 500+ pieces of software — GitHub is…
npm Supply Chain Attacks: Why They Keep Happening and How to Defend
Why npm keeps getting hit with malicious packages, what makes Node's registry uniquely exposed, and a practical defense stack (Socket, Snyk, lockfile audits, --ignore-scripts) for …
Ask HN: How are you stopping supply chain attacks via compromised dev keys?
Clasp: A four-stage supply-chain attack pattern via emergency patches
An attack pattern that turns emergency patch discipline into a rapid distribution system for malware. Organizations with the best patching cycles are compromised first.…
TeamPCP Supply Chain Campaign: Update 008
TeamPCP Supply Chain Campaign: Update 008 - 26-Day Pause Ends with Three Concurrent Compromises (Checkmarx KICS, Bitwarden CLI Cascade, xinference PyPI), CanisterSprawl npm Worm Id…