Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
TrapDoor Supply Chain Attack: Credential-Stealing Malware in npm, PyPI, and Crates.io
Introduction A sophisticated and coordinated supply chain attack, codenamed TrapDoor, has been actively targeting the developer ecosystem si...
Supply Chain Attacks: Detecting `node-ipc`, `@antv`, and Malicious GitHub Actions
Introduction The latest Security Affairs Malware Newsletter (Round 98) highlights a disturbing convergence of supply chain compromises targe...
npm Staged Publishing: Hardening the Software Supply Chain with 2FA-Gated Releases
Introduction GitHub has officially released Staged Publishing for the npm registry, a critical control designed to sever the attack chain us...
TeamPCP Mini Shai-Hulud: Detection and Remediation for npm and PyPI Supply Chain Worm
Introduction Between September 2025 and May 2026, the threat actor group TeamPCP executed a sophisticated supply chain attack dubbed "Mini S...
Mini Shai Hulud: @antv npm Supply Chain Attack & CI/CD Credential Theft
Introduction The software supply chain has suffered a significant blow with the discovery of a malicious campaign targeting the @antv npm ec...
TanStack npm Supply Chain Attack: Detecting Nx Console Compromise & GitHub Token Theft
Introduction GitHub has confirmed that the breach of 3,800 internal source code repositories was the direct result of a sophisticated supply...
Grafana GitHub Source Code Exfiltration via TanStack npm Supply Chain Attack — IR Guide
Introduction On May 19, 2026, Grafana Labs disclosed a significant security incident confirming that their GitHub environment was breached, ...
Shai-Hulud Supply Chain Attack: Detection and Remediation for 600 Compromised npm Packages
Introduction A massive supply-chain attack campaign, dubbed "Shai-Hulud," has flooded the Node Package Manager (npm) registry with over 600 ...
Malicious npm Packages: Infostealers and Phantom Bot DDoS — Detection and Removal Guide
Introduction Security researchers have identified a fresh wave of malicious packages targeting the npm ecosystem, specifically designed to c...