Supply Chain Security
26 articles RSS
GitHub Extends Malware Advisory Detection Beyond npm to Eight Package Ecosystems, Absorbing OpenSSF's Malicious-Packages Database
GitHub now feeds Dependabot malware alerts from OpenSSF's malicious-packages data across npm, PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer.
Six npm Packages Compromised to Pull Malware Command-and-Control Addresses From Ethereum Transactions
Sonatype found six npm packages that decode malware C2 server IPs from Ethereum transaction bytes, using a technique tied to North Korea's Contagious Interview campaign.
GitHub Ships an Actions Network Firewall in Technical Preview, Consolidates Months of npm and Actions Supply Chain Hardening
GitHub detailed a technical-preview Actions network firewall and rounded up npm and Actions defaults changed since February, drawing sharp Hacker News debate over delay-based defenses versus package signing.
Sonatype Tracks 'Flooding Dropper' Campaign Flooding npm With 846 Malicious Packages Across Disposable Accounts
Sonatype is tracking sonatype-2026-005660, a campaign that has published 846 malicious npm packages across throwaway accounts, dropping cross-platform malware with DNS-based fallback delivery.
ChainDrop Worm Compromises Over 1,300 npm Package Versions After keyv Maintainer's GitHub Account Is Breached
A self-propagating worm hijacked keyv and related npm packages on August 4 after a maintainer's GitHub account was breached, spreading to 1,300+ package versions.
FINOS Announces Intent to Form OSERA, a Bank-Led Alliance to Mutualize Open Source Patching
Five banks piloted a shared open source patching alliance; FINOS says AI-accelerated vulnerability discovery makes mutualized fixes urgent.
Linux Foundation Launches Akrites, an Industry Alliance to Patch Open Source Flaws Before AI Turns Them Into Exploits
The Linux Foundation and roughly 20 companies including AWS, Anthropic, Google, IBM and major banks launched Akrites, a coordinated incident-response alliance for open source software, after finding fewer than 5% of recently surfaced vulnerabilities have been patched.
GitHub Makes a Three-Day Package Cooldown the Default for Dependabot Version Updates, Citing Supply-Chain Attacks Through New Releases
Dependabot now waits three days before proposing new dependency versions by default. GitHub says the delay keeps freshly compromised releases out of update pull requests; security updates are exempt and repositories can opt out.
IBM and Red Hat Expand Lightwell With Commercial Offerings to Secure Open Source Software Supply Chains
IBM and Red Hat launched commercial Lightwell offerings on July 8, building on their $5 billion pledge to secure open source software supply chains.
npm v12 Ships With Install Scripts Disabled by Default After a Year of Supply-Chain Attacks
npm v12 disables install scripts, Git dependencies, and remote-URL dependencies by default, closing the execution path several npm worms exploited over the past year.
Fifteen Malicious JetBrains Marketplace Plugins Stole AI API Keys From Nearly 70,000 Developer Installs Before JetBrains Purged Them
A coordinated campaign published 15 fake AI coding assistants on the JetBrains Marketplace that harvested developer API keys; JetBrains removed them and terminated 7 publisher accounts.
TrapDoor Campaign Deploys 34 Malicious Packages Across npm, PyPI, and Crates.io, Weaponizing AI Coding Assistants to Steal Crypto Wallets
Socket researchers discovered TrapDoor, a supply chain attack spanning 34 packages and 384+ versions across three registries, with a novel technique that embeds hidden instructions in AI coding assistant config files to trigger credential exfiltration.