Supply Chain Security
9 articles RSS
FINOS Announces Intent to Form OSERA, a Bank-Led Alliance to Mutualize Open Source Patching
Five banks piloted a shared open source patching alliance; FINOS says AI-accelerated vulnerability discovery makes mutualized fixes urgent.
Linux Foundation Launches Akrites, an Industry Alliance to Patch Open Source Flaws Before AI Turns Them Into Exploits
The Linux Foundation and roughly 20 companies including AWS, Anthropic, Google, IBM and major banks launched Akrites, a coordinated incident-response alliance for open source software, after finding fewer than 5% of recently surfaced vulnerabilities have been patched.
GitHub Makes a Three-Day Package Cooldown the Default for Dependabot Version Updates, Citing Supply-Chain Attacks Through New Releases
Dependabot now waits three days before proposing new dependency versions by default. GitHub says the delay keeps freshly compromised releases out of update pull requests; security updates are exempt and repositories can opt out.
IBM and Red Hat Expand Lightwell With Commercial Offerings to Secure Open Source Software Supply Chains
IBM and Red Hat launched commercial Lightwell offerings on July 8, building on their $5 billion pledge to secure open source software supply chains.
npm v12 Ships With Install Scripts Disabled by Default After a Year of Supply-Chain Attacks
npm v12 disables install scripts, Git dependencies, and remote-URL dependencies by default, closing the execution path several npm worms exploited over the past year.
Fifteen Malicious JetBrains Marketplace Plugins Stole AI API Keys From Nearly 70,000 Developer Installs Before JetBrains Purged Them
A coordinated campaign published 15 fake AI coding assistants on the JetBrains Marketplace that harvested developer API keys; JetBrains removed them and terminated 7 publisher accounts.
TrapDoor Campaign Deploys 34 Malicious Packages Across npm, PyPI, and Crates.io, Weaponizing AI Coding Assistants to Steal Crypto Wallets
Socket researchers discovered TrapDoor, a supply chain attack spanning 34 packages and 384+ versions across three registries, with a novel technique that embeds hidden instructions in AI coding assistant config files to trigger credential exfiltration.
npm Ships Staged Publishing and Install-Source Allowlists in CLI 11.15.0, Requiring Human 2FA Approval Before Packages Go Live
GitHub's npm registry makes staged publishing generally available: packages must pass a human-approved, 2FA-gated queue before consumers can install them.
Mini Shai-Hulud Worm Hits TanStack, Mistral AI and UiPath, Compromising 170+ npm and PyPI Packages With 518M Combined Downloads
TeamPCP's May 11 supply-chain attack abused a pull_request_target workflow, GitHub Actions cache poisoning, and OIDC token theft to ship 84 malicious TanStack versions and spread to Mistral AI, UiPath and others.