Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
npm Supply Chain Attacks: Detecting Shai Hulud-style Malware and CI/CD Persistence
Introduction The JavaScript ecosystem is currently the battleground for one of the most sophisticated supply chain campaigns we've seen in y...
Axios npm Supply Chain Attack: Detection and Incident Response for Versions 1.14.1 and 0.30.4
Introduction The widely popular HTTP client Axios has been confirmed compromised in a critical supply chain attack. Malicious versions 1.14....
Axios NPM Supply Chain Compromise: Detecting Industrialized Social Engineering and Malicious Packages
Introduction The recent attack on the axios NPM package is a wake-up call for the software development lifecycle. Threat actors have moved b...
How to Defend Against Malicious npm Packages Targeting Redis and PostgreSQL
How to Defend Against Malicious npm Packages Targeting Redis and PostgreSQL Introduction In a recent supply chain attack, cybersecurity rese...
Defending Against UNC1069: Strategies to Mitigate npm Supply Chain Attacks
In a stark reminder of the evolving threat landscape, the maintainer of the popular Axios npm package recently confirmed a supply chain comp...
Critical Supply Chain Attack on Axios NPM: Detection and Incident Response Guide
Critical Supply Chain Attack on Axios NPM: Detection and Incident Response Guide Introduction In a disturbing development for the JavaScript...
Defending Against the Axios npm Supply Chain Attack: Detection and Remediation
Defending Against the Axios npm Supply Chain Attack: Detection and Remediation\n\n Introduction\n\nOn March 31, a sophisticated supply chain...
How to Defend Against the Axios npm Supply Chain Attack by UNC1069
How to Defend Against the Axios npm Supply Chain Attack by UNC1069 Introduction Software supply chains have become the primary attack vector...