Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
npm v12 Security Overhaul: Mitigating Supply-Chain Attacks in CI/CD
Introduction GitHub has announced the upcoming release of npm v12, scheduled for next month, introducing significant security modifications ...
IronWorm npm Supply-Chain Attack: Detection and Incident Response Guide
IronWorm npm Supply-Chain Attack: Detection and Incident Response Guide Introduction A significant supply-chain attack has struck the JavaSc...
Red Hat npm Supply-Chain Attack: Detecting and Remediating Shai-Hulud Miasma Credential Theft
Introduction A critical supply-chain attack has compromised more than 30 npm packages within Red Hat's '@redhat-cloud-services' namespace, d...
Mini Shai-Hulud Campaign: Detecting Typosquatted npm Supply Chain Attacks
Introduction The "Mini Shai-Hulud" campaign represents a significant escalation in supply chain tactics, specifically targeting the software...
Download Pumping: npm Supply Chain Deception — Detection and Hardening Guide
Introduction The trust model in the open-source ecosystem is broken. For years, developers have relied on download counts as a primary heuri...
TrapDoor Supply Chain Attack: Credential-Stealing Malware in npm, PyPI, and Crates.io
Introduction A sophisticated and coordinated supply chain attack, codenamed TrapDoor, has been actively targeting the developer ecosystem si...
Supply Chain Attacks: Detecting `node-ipc`, `@antv`, and Malicious GitHub Actions
Introduction The latest Security Affairs Malware Newsletter (Round 98) highlights a disturbing convergence of supply chain compromises targe...
npm Staged Publishing: Hardening the Software Supply Chain with 2FA-Gated Releases
Introduction GitHub has officially released Staged Publishing for the npm registry, a critical control designed to sever the attack chain us...
TeamPCP Mini Shai-Hulud: Detection and Remediation for npm and PyPI Supply Chain Worm
Introduction Between September 2025 and May 2026, the threat actor group TeamPCP executed a sophisticated supply chain attack dubbed "Mini S...