Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
North Korea-Linked npm Supply Chain Attack: Rollup Polyfill Mimicry Detection
North Korea-Linked npm Supply Chain Attack: Rollup Polyfill Mimicry Detection Introduction A sophisticated supply chain attack has been iden...
PolinRider Campaign: Defending Against North Korean Supply Chain Attacks in npm, Go, and Chrome
Introduction The threat landscape for software development environments has deteriorated significantly with the emergence of the PolinRider ...
Supply Chain Alert: Hijacked npm and Go Packages Using VS Code Tasks to Deploy Python Infostealers
Introduction In June 2026, JFrog security researchers uncovered a sophisticated supply chain attack targeting the open-source ecosystem. Thi...
Miasma Supply Chain Attack: Detection and Remediation for npm and GitHub Actions Abuse
Introduction The open-source supply chain remains a primary vector for sophisticated adversaries in 2026. Security researchers have identifi...
Miasma Campaign: Detecting npm Supply Chain Attacks Bypassing SLSA Level 3
Introduction The Miasma campaign marks a disturbing evolution in open-source supply chain warfare. By leveraging a stolen session cookie tha...
Malicious npm Packages Impersonating PostCSS: Windows RAT Detection and Remediation
Malicious npm Packages Impersonating PostCSS: Windows RAT Detection and Remediation Introduction In June 2026, the software supply chain fac...
Mastra AI Supply Chain Attack: NPM Compromise Detection and Response
Mastra AI Supply Chain Attack: NPM Compromise Detection and Response Date: May 12, 2026 Author: Senior Security Consultant, Security Arsenal...
Threat Intelligence Roundup: Defending Against Miasma npm Worm and Gafgyt C0XMO
Introduction The latest Security Affairs malware newsletter (Round 101) highlights a disturbing trend in active threat landscapes: the weapo...
NPM 12 Hardening: Mitigating Supply Chain Attacks via Dependency Script Blocking
Introduction In 2026, the software supply chain remains the most significant attack surface for modern organizations. The recent announcemen...