Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
npm Supply Chain Attacks: Detecting Shai Hulud-style Malware and CI/CD Persistence
Introduction The JavaScript ecosystem is currently the battleground for one of the most sophisticated supply chain campaigns we've seen in y...
Bitwarden NPM Package Supply Chain Attack: Detection and Remediation Guide
Bitwarden NPM Package Supply Chain Attack: Detection and Remediation Guide Introduction Bitwarden, a popular password manager, has been impa...
Npm Supply Chain Attack: Worm-Like Propagation and Credential Theft — Detection and Remediation
Introduction A sophisticated supply chain attack targeting the npm registry has been identified, characterized by worm-like propagation capa...
Bitwarden CLI npm Compromise: Detecting Malicious @bitwarden/cli Packages (v2024.8.0, v2024.7.1)
Introduction The software supply chain was struck again when attackers compromised the official Bitwarden CLI npm package, @bitwarden/cli. B...
Axios npm Supply Chain Attack: Emergency Detection and Incident Response for Malicious Versions 1.14.1 and 0.30.4
Introduction A confirmed supply chain attack has compromised the Axios npm package, one of the most widely used HTTP client libraries in the...
Axios npm Supply Chain Compromise: Detection & Remediation for Versions 1.14.1 and 0.30.4
Introduction On March 31, 2026, the JavaScript ecosystem faced a critical supply chain assault. The Cybersecurity and Infrastructure Securit...
UNC1069 Axios Supply Chain Attack: Detection and Remediation for Malicious npm Packages
UNC1069 Axios Supply Chain Attack: Detection and Remediation for Malicious npm Packages Introduction On March 31, the open-source ecosystem ...
NPM Supply Chain Attack: Malicious Axios Versions (1.6.0-1.6.2) Detection and Remediation
Introduction The open-source ecosystem suffered a significant trust breach when the popular HTTP client library Axios was compromised. Threa...
Axios npm Supply Chain Attack: Detection and Incident Response for Versions 1.14.1 and 0.30.4
Introduction The widely popular HTTP client Axios has been confirmed compromised in a critical supply chain attack. Malicious versions 1.14....