Supply-chain-security is a topic tracked in our intelligence system with 5 linked articles.
A credential-stealing npm worm linked to Keyv infected hundreds of packages; SafeDep found 353 poisoned versions across 79 package names, with a wider footprint of 442 versions across 353 names, and Aikido estimates at least 868 affected packages.
Two compromised joyfill npm packages execute a RAT on import, highlighting software supply-chain risk in Node.js ecosystems.
DepsGuard is an active open-source Rust tool that hardens npm/pnpm/yarn/bun/uv configs via an interactive UI with backups and restore, backed by recent updates and a security-focused feature set.
A jqwik 1.10.0 protestware incident embeds stdout commands aimed at coding agents, illustrating a new supply-chain risk vector with regulatory/compliance signals and ecosystem implications.
CrowdStrike and Google helped takedown the Glassworm botnet that infected 300+ GitHub repos and used multiple C2 channels, highlighting open-source supply-chain risk and unclear legal authority for takedowns.
npm adds staged publishing (GA) and new install-time allow flags, enforcing explicit approvals and explicit source allowlists, with versioned requirements and a future default change for git sources.
Subscribe for real-time topic updates and unlimited access to our intelligence platform.