Supply chain
Dependency attacks, model integrity, and signing
Resources 315
- Zero-dependency MCP server implementation.github.com
- model-signingpypi.org
- Supply chain security for MLgithub.com
- Design WIP Market Report AI Security - Final.pdfdrive.google.com
- Axios Developer Tool Compromiseopenai.com
- 11 minutes was all it took to hack GitHub - poisoned nx console VS Code extension by teampcpx.com
- 20 Days Later: Trivy Compromise, Act IIlabs.boostsecurity.io
- 3CX Software Supply Chain Compromise Investigation - Mandiantmandiant.com
- 8 Million Requests Later, We Made The SolarWinds Supply Chain Attack Look Amateurlabs.watchtowr.com
- @ctrl/tinycolor Supply Chain Attack Post-mortemsigh.dev
- A backdoor in xz - LWNlwn.net
- A Comprehensive Study on the Impact of Vulnerable Dependencies on Open-Source Softwarearxiv.org
- A New Kali Linux Archive Signing Keykali.org
- A Reality Check on SBOM-based Vulnerability Management: An Empirical Study and A Path Forwardarxiv.org
- Abusing Go's infrastructurereverse.put.as
- ActionsCacheBlasting - GitHub Actions cache poisoning proof-of-conceptgithub.com
- Adnan Khan finds another GitHub Action compromised like tj-actions/changed-filesx.com
- Adnan Khan on TeamPCP backdooring the Checkmarx Jenkins AST plugin with Dune-themed malwarex.com
- Agent of Chaos: Hijacking NodeJS's Jenkins Agentspraetorian.com
- ai-bom - AI Bill of Materials scanner to discover every AI agent, model and API in your infrastructuregithub.com
- Aikido Intel - Real-time vulnerability and malware intelligence for open source packagesintel.aikido.dev
- Akrites - Coordinated, confidential vulnerability remediation for open source softwareakrites.org
- Announcing Chalk Alpha - open-source software provenancecrashoverride.com
- Announcing the deps.dev API: critical dependency data for secure supply chainssecurity.googleblog.com
- Anton on building an LLM-powered supply chain audit system with Claude - ClaudeForBlueTeam Day 16x.com
- Anza on the @solana/web3.js npm compromise pushing malicious versions 1.95.6 and 1.95.7x.com
- Apiiro: Malicious Code Campaign Using a GitHub Repo Confusion Attackapiiro.com
- Arch Linux disables AUR package adoption amid malicious activitylists.archlinux.org
- Arch Linux's reproducible source tarballs caught the xz backdoorsocial.treehouse.systems
- Attackers Are Impersonating a Linux Foundation Leader in Slack to Target Open Source Developerssocket.dev
- awesome-cicd-attacks - Practical resources for offensive CI/CD security researchgithub.com
- Ax Sharma on GitHub flaw letting malware appear hosted on Microsoft's official reposx.com
- Axios npm Supply Chain Compromise - Full RE, Dynamic Analysis and BlueNoroff Attributiongist.github.com
- Axios npm supply chain compromise analysis - Joe Desimone gistgist.github.com
- Azure DevOps Zero-Click CI/CD Vulnerability - Legit Securitylegitsecurity.com
- Backdoor in upstream xz/liblzma leading to SSH server compromisenews.ycombinator.com
- Backstabber's Knife Collection - A Review of Open Source Software Supply Chain Attacksarxiv.org
- bagel - CLI that inventories security-relevant metadata on developer workstationsgithub.com
- Binarly launches xz.fail API for bulk scanning the xz backdoorx.com
- Binarly XZ backdoor detectorxz.fail
- bogrod - manage SBOM and VEX like source codegithub.com
- Booz Allen Analysis Reveals Risks in Using Chinese AI Models for America's Software Supply Chaininvestors.boozallen.com
- Brian Krebs on attribution in the XZ backdoorinfosec.exchange
- Building a Supply Chain Attack with .NET and NuGetblog.maartenballiauw.be
- bumblebee - developer endpoint scanner for supply-chain compromise exposuregithub.com
- Bybit hack update: Lazarus compromised Safe Wallet's AWS S3 bucket to inject malicious JavaScriptx.com
- Bypassing egress filtering in BullFrog GitHub Actiondevansh.bearblog.dev
- Catching the LiteLLM PyPI Attack: The Full Claude Code Transcriptfuturesearch.ai
- cdxgen v9.6.0 release - CycloneDX SBOM generatorgithub.com
- CERT-EU: European Commission cloud breach - a supply-chain compromise via Trivycert.europa.eu
- Chainloop - software supply chain evidence store and policy engine for attestations, SBOMs and VEXgithub.com
- Chalk - software provenance and attestation from build to productiongithub.com
- Chinese Implants in the Supply Chain - VulnCheck traces the ZBT router supply chainvulncheck.com
- Christopher Stanley on the Cyberhaven breach - malicious Chrome extension and IOCsx.com
- CICD-Goat Setup and Easy Challenge Walkthrough - WhiteRabbit, MadHatter, Duchessphilkeeble.com
- Clément Dumas on npm squatting of Anthropic-internal package names after Claude Code source leakx.com
- Code Signing is not Enoughianlewis.org
- CodeQLEAKED - Public Secrets Exposure Leads to Supply Chain Attack on GitHub CodeQLpraetorian.com
- Compromised Chrome extensions tracking spreadsheet - December 2024 extension supply-chain attackdocs.google.com
- Continuous hardening of Chainguard's internal software supply chainchainguard.dev
- Could lockfiles just be SBOMsnesbitt.io
- CramHacks #24 - software supply chain security newslettercramhacks.com
- CramHacks - Public Affected Functionscramhacks.com
- CVE-2023-1767 - Stored XSS on Snyk Advisor allows fabrication of npm package health scoresweizman.github.io
- CVE-2023-49291 and More - A Potential Actions Nightmareadnanthekhan.com
- Cyberhaven Extension Compromise - Live Incident Trackerextensiontotal.com
- Cyberhaven's Preliminary Analysis of the Malicious Chrome Extension Attackcyberhaven.com
- Dangerous by default: Insecure GitHub Actions found in MITRE, Splunk, and other open source repositoriessysdig.com
- DataDog malicious-software-packages-dataset - vetted malicious npm, PyPI and AI Skills packagesgithub.com
- dax on npm revoking every npm token and moving to OIDCx.com
- Deceptive Deprecation: The Truth About npm Deprecated Packagesblog.aquasec.com
- Deep Dive into the CISA and NSA Best Practices for CI/CD Environments - Anchore Webinaranchore.com
- DEF CON 31 - The GitHub Actions Worm - Asi Greenholtsyoutube.com
- Dependabot user-defined rules for security updates and alertsgithub.blog
- Dependabot version updates introduce default package cooldowngithub.blog
- Dependency Confusions in Docker and remote pwning of your infraerrno.fr
- Dependency Cooldowns - configuring package manager cooldowns to defend against supply chain attackscooldowns.dev
- Dependency cooldowns are unfair; we should use phased rollouts insteadillegalcode.net
- Deprecation Notice - Dependabot to Drop Support for Python 3.6 and 3.7github.blog
- deps.dev - Open Source Insights dependency and vulnerability explorerdeps.dev
- depsguard - harden package manager configs against supply chain attacksgithub.com
- Deptective - Trail of Bits tool that determines native dependencies for any programgithub.com
- Detect and control software package downloads with package registry securitydevelopers.cloudflare.com
- Diving into PyPI package name squattingblog.orsinium.dev
- Do you know if all your repositories have up-to-date dependencies - GitHub Evergreen and Dependabotgithub.blog
- Docker Hardened Images for every developerdocker.com
- DPRK Contagious Interview Malware Weaponizes VS Code Tasks - OpenSourceMalwareopensourcemalware.com
- DuckDB NPM packages 1.3.3 and 1.29.2 compromised with malware - GitHub advisorygithub.com
- echarts-for-react npm supply chain compromisegithub.com
- Elastic releases detections for the Axios supply chain compromiseelastic.co
- Elf-Stats NPM Christmas Spam Campaignopensourcemalware.com
- Everything I Know About the XZ Backdoorboehs.org
- Exposing Infection Techniques Across Supply Chains and Codebasestrendmicro.com
- Fake GitHub projects distribute stealers in GitVenom campaignsecurelist.com
- Feross: TeamPCP's own advice for defenders - pin hashes, least-privilege tokens, and use Socketx.com
- fickling - Python pickle decompiler and static analyzer for malicious ML model filesgithub.com
- Filippo Valsorda on the xz backdoor - RCE via hooked RSA_public_decrypt, gated by Ed448 signaturebsky.app
- Filippo Valsorda: xz backdoor is gated RCE via Ed448-signed payload, not an auth bypassbsky.app
- Finding and utilising leaked code signing certificatestij.me
- Finding Software Supply Chain Attack Paths with Logical Attack Graphsarxiv.org
- Forging signed commits on GitHubiter.ca
- Gato - GitHub Actions pipeline enumeration and attack toolkit, superseded by Trajangithub.com
- Gato-X - GitHub Actions static analysis and exploit toolkitgithub.com
- Generation of VEX documents by the Kubescape relevancy engine - kubevuln issue #155github.com
- gh-sbom - generate SBOMs with the gh CLIgithub.com
- GitHub Actions Security - Legit Security whitepaperlegitsecurity.com
- GitHub Actions Supply Chain Attack - Coinbase and the tj-actions/changed-files Incidentunit42.paloaltonetworks.com
- GitHub Advisory Database - reviewed npm advisoriesgithub.com
- GitHub on internal repo access via a poisoned VS Code extension on an employee devicex.com
- GitHub Repos Used for Distributing Malwarecheckmarx.com
- GitHub roadmap: Immutable Actions Publishing for GitHub Actionsgithub.com
- GitHub search for 'Shai-Hulud Repository' repos created by the npm wormgithub.com
- GitHub security alert: social engineering campaign targets technology industry employeesgithub.blog
- google/oss-rebuild - securing open-source package ecosystems with build attestationsgithub.com
- Grafana security update: no customer impact from GitHub workflow vulnerabilitygrafana.com
- guac - aggregates software supply chain security metadata into a graphgithub.com
- Hackers are spoofing themselves as GitHub's Dependabot to steal user passwordsitpro.com
- Hat Trick: AWS introduced same RCE vulnerability three times in four yearsgiraffesecurity.dev
- heisenberg-ssc-gha - dependency health check GitHub Action for supply chain securitygithub.com
- Helm advisory: Chart dependency updating with malicious Chart.yaml content and symlinkgithub.com
- Homebrew pins xz to 5.4.6 after the xz backdoor - Discussion #5243github.com
- How Dependabot Actually Worksnesbitt.io
- How I Got Hacked: A Warning about Malicious PoCschocapikk.com
- How My Homemade NPM Hunter Caught a Mini Shai-Hulud Packageinf0stache.substack.com
- How Quickly Do Development Teams Update Their Vulnerable Dependencies?arxiv.org
- How the TanStack npm attack happened via GitHub Actions cache poisoningx.com
- How to Curate VS Code Remote Repositories - JFrog Curation for AI editor extensionsdocs.jfrog.com
- How to gain code execution on millions of people and hundreds of popular apps - ToDesktopkibty.town
- How we got hit by Shai-Hulud: A complete post-mortem - Trigger.devtrigger.dev
- How We Hacked a Software Supply Chain for $50Klandh.tech
- How we pwned X, Vercel, Cursor, Discord, and hundreds of companies through a supply-chain attackgist.github.com
- Identifying the Supply Chain of AI for Trustworthiness and Risk Management in Critical Applicationsarxiv.org
- Immutable Tag - guaranteeing immutability of version control tags with blockchainimmutable-tag.github.io
- Improving Supply Chain Security for Rust Through Artifact Signingfoundation.rust-lang.org
- Incident Timeline - TeamPCP Supply Chain Campaign and the Trivy compromiseramimac.me
- Inside the failed attempt to backdoor SSH globally that got caught by chance - XZ supply chaindoublepulsar.com
- International Cyber Digest: S&P Global hit by TeamPCP Trivy and LiteLLM supply chain attacksx.com
- Introducing Frizbee - securing GitHub Actionsstacklok.com
- Introducing MavenGate: a supply chain attack method for Java and Android applicationsblog.oversecured.com
- Introducing npm package provenancegithub.blog
- Introducing Package Proxy: supply-chain safety checks without client-side softwareblog.thinkst.com
- Introducing safe npm - a Socket npm wrappersocket.dev
- Introducing Socket Firewall: Free, Proactive Protection for Your Software Supply Chainsocket.dev
- Introducing Supply-Chain Firewall: Protecting Developers from Malicious Open Source Packages - Datadogsecuritylabs.datadoghq.com
- Investigating Two Variants of the Trivy Supply-Chain Compromisekudelskisecurity.com
- Jeff Cross on the malicious Nx Console 18.95.0 possibly hitting 6k installsx.com
- jest-canvas-mock npm supply chain compromise - GitHub issuegithub.com
- Joe Desimone on an AI harness monitoring PyPI and npm diffs that caught the Axios compromisex.com
- John Hultquist: axios supply chain compromise attributed to DPRK actor UNC1069x.com
- Journey to the Center of Software Supply Chain Attacksarxiv.org
- JSSCM - JavaScript Supply Chain Monitor detecting expired domains for stored XSSgithub.com
- KEIP - eBPF/LSM tool that blocks malicious network activity during pip installgithub.com
- Keyv and friends compromised in npm supply chain attackaikido.dev
- KitOps - packaging, versioning and sharing AI projects as OCI ModelKitskitops.ml
- LavaMoat - tools for sandboxing your JavaScript dependency graph against supply chain attacksgithub.com
- Lessons Learned from 2024's Supply Chain Attackscramhacks.com
- Leveraging VSCode Extensions for Initial Accessmdsec.co.uk
- liblzma and xz version 5.6.0 and 5.6.1 are vulnerable to arbitrary code execution compromisexeiaso.net
- List of issues discovered with open source SBOM generators - sbomqs discussiongithub.com
- LiteLLM - pin Trivy version in security scans CIgithub.com
- LiteLLM 1.82.7 and 1.82.8 PyPI packages compromisednews.ycombinator.com
- LiteLLM Breach Checker: Is Your Organization Exposed?exposure.cloudsek.com
- LOTP - Living Off the Pipelineboostsecurityio.github.io
- Malicious code in Lottie-Player CDN files - LottieFiles issue #254github.com
- Malicious litellm_init.pth credential stealer in litellm 1.82.8 PyPI package - GitHub issuegithub.com
- Malware in @solana/web3.js npm packagegithub.com
- Malware in Open VSX: These Vibes Are Off - extension risks for AI code editorssecureannex.com
- Marketplace Takeover: How We Could've Taken Over Every Developer Using a VSCode Forkblog.koi.security
- Megalodon: Mass GitHub Repo Backdooring via CI Workflows - SafeDepsafedep.io
- Microsoft's durabletask PyPI Package Compromised in Supply Chain Attackstepsecurity.io
- Mini Shai-Hulud Strikes Again - 317 npm Packages Compromisedsafedep.io
- Mitchell Hashimoto on forking and pinning dependencies to reduce supply chain attack riskx.com
- Mitigated API authentication bypass for python.org download metadatapyfound.blogspot.com
- New details reveal how hackers hijacked 35 Google Chrome extensionsbleepingcomputer.com
- New GitHub Action supply chain attack - reviewdog/action-setupwiz.io
- New year, new image: Introducing the Chainguard Images Directorychainguard.dev
- NIST SP 800-204D - Strategies for the Integration of Software Supply Chain Security in DevSecOps CI/CD Pipelinesnvlpubs.nist.gov
- No one owes you supply-chain securitypurplesyringa.moe
- npm 'accidentally' removes Stylus package, breaks builds and pipelinesbleepingcomputer.com
- npm Malware Cluster Uses Hidden README Payloads to Trigger Credential Theftinf0stache.substack.com
- Npm Package Targeting GitHub-Owned Repositories Flagged as Red Team Exercisethehackernews.com
- npm publish-time malware scanning and dual-use metadatagithub.blog
- NPM-Threat-Emulation - atomic tests for validating npm supply-chain attack detectionsgithub.com
- NSA and CISA - Defending Continuous Integration/Continuous Delivery CI/CD Environmentsmedia.defense.gov
- Nx Console VS Code Extension Compromised - malicious version steals developer credentials and CI/CD secretsstepsecurity.io
- One Supply Chain Attack to Rule Them All - Poisoning GitHub's Runner Imagesadnanthekhan.com
- Open VSX publish-extensions fix commit - use separate jobs instead of child_processgithub.com
- OpenAI on the Axios library security incident and macOS app certificate updatesx.com
- opengrep PyPI package temporarily taken over - security advisorygithub.com
- OpenSourceMalware API - one API to query open source malware threat intelopensourcemalware.com
- OpenSourceMalware.com threat intel entry for aquasecurity/trivyopensourcemalware.com
- oss-security - backdoor in upstream xz/liblzma leading to ssh server compromiseopenwall.com
- OSSGadget - tools for analyzing open source packagesgithub.com
- OSV - Open Source Vulnerabilities databaseosv.dev
- Package Manager Design Tradeoffsnesbitt.io
- PackageGate: 6 zero-days in JS package managers, but npm won't actkoi.ai
- Packj - flags malicious and risky open-source packagesgithub.com
- Paul Vann on Ghost by Validia - agent-based package change monitoring against supply chain attacksx.com
- PBOM.dev - Open Software Supply Chain Security Framework and OSC&Rpbom.dev
- Phantom in the Vault: Obsidian Abused to Deliver PhantomPulse RATelastic.co
- PKfail: Untrusted Platform Keys Undermine Secure Boot - Binarly research report22222483.fs1.hubspotusercontent-na1.net
- Playing with Fire - How We Executed a Critical Supply Chain Attack on PyTorchjohnstawinski.com
- Please Stop Sending Me Nested Dependency Security Reportsjoshuakgoldberg.com
- pnpm 10.0.0 Blocks Lifecycle Scripts by Defaultsocket.dev
- Poisoned Pipeline Execution Attacks: A Look at CI-CD Environmentsbishopfox.com
- Poisoning Pipelines: Azure DevOps Editionlabs.jumpsec.com
- Polyfill supply chain attack hits 100K+ sitessansec.io
- Post Mortem: axios npm supply chain compromisegithub.com
- Post-mortem of Shai-Hulud attack on November 24th, 2025posthog.com
- poutine - supply chain vulnerability scanner for build pipelinesgithub.com
- Principles for Package Repository Securityrepos.openssf.org
- Principles for Package Repository Security v0.2github.com
- Protect your open source project from supply chain attacksopensource.googleblog.com
- Public Security Advisory regarding Malicious versions of Nx - GitHub issuegithub.com
- PyPI incident report: token exfiltration campaign via GitHub Actions workflowsblog.pypi.org
- PyPI Introducing Trusted Publishers - OIDC-based secure package publishingblog.pypi.org
- Rami McCarthy on Mini Shai-Hulud fallout - 49 Microsoft/Azure GitHub repos removedx.com
- Rami McCarthy shares a visualization of the keyv worm's spreadx.com
- RCE Vulnerability in Azure Pipelines Can Lead to Software Supply Chain Attack - CVE-2023-21553legitsecurity.com
- react-native-international-phone-number release 0.12.1 is compromisedgithub.com
- Reduce dependencies of libsystemd - systemd issue after the xz backdoor CVE-2024-3094github.com
- Risk Explorer for Software Supply Chainssap.github.io
- ruby nealon on the CVE-2024-3094 xz supply-chain attack and auditing OSS contributorsx.com
- running-qix-malware - how the compromised Qix npm packages could have been stoppedgithub.com
- S1ngularity/nx attackers strike again - first-of-its-kind npm worm payloadaikido.dev
- s1ngularity: Nx npm supply chain attack leaks secrets on GitHub - everything you need to knowwiz.io
- S3C2 Summit 2025-03: Industry Secure Supply Chain Summitarxiv.org
- SafeDep MCP Server - real-time malicious package threat intelligence for AI coding agentssafedep.io
- SANDWORM_MODE: Shai-Hulud-Style npm Worm Hijacks CI Workflows and Poisons AI Toolchainssocket.dev
- SAP Risk Explorer for Software Supply Chains - taxonomy of open source supply chain attackssap.github.io
- sbomqs - SBOM quality and compliance scoring toolgithub.com
- scarno - dependency pruner flagging unused, undeclared and suspicious dependenciesgithub.com
- secure-supply-chain-on-aks - securing container deployments with open-source toolsgithub.com
- Securing Machine Learning Models - A Comprehensive Guide to Model Scanningrepello.ai
- Self-spreading GlassWorm malware hits OpenVSX, VS Code registriesbleepingcomputer.com
- Shai-Hulud 2.0 npm worm - Datadog Security Labs writeupsecuritylabs.datadoghq.com
- Shai-Hulud 2.0 Supply Chain Attack: npm worm exposes 25K+ reposwiz.io
- Shai-Hulud Returns: Over 1K NPM Packages and 27K+ GitHub Repos Infected via Fake Bun Runtimehelixguard.ai
- Sigstore - sign, verify and protect software supply chain artifactssigstore.dev
- sketchy - scan repos for malicious patterns before you git clone or installgithub.com
- slsa-github-generator - language-agnostic SLSA provenance generation for GitHub Actionsgithub.com
- Socket Acquires Coana to Bring Reachability Analysis to Every Appsec Teamsocket.dev
- Socket acquires Secure Annex to expand extension security across browsers, IDEs and AI toolssocket.dev
- Software Heritage archive of the xz-utils backdoor revisionarchive.softwareheritage.org
- Software Supply Chain Security of Web3arxiv.org
- Software with politic opinion is a security threatvitonsky.net
- SolanaFloor: attacker behind the September 2025 npm supply-chain attack stole only $66x.com
- Spooky Skills - Agent Skill Supply Chain Risksramimac.me
- Stacklok has contributed Minder to the OpenSSFstacklok.com
- Staged publishing for npm packages - npm Docsdocs.npmjs.com
- StepSecurity Secure Workflow - harden GitHub Actions workflowsapp.stepsecurity.io
- Supply chain nightmare: How Rust will be attacked and what we can do to mitigate the inevitablekerkour.com
- Supply Chain Reaction: Enhancing the Precision of Vulnerability Triage using Code Reachability Informationharshvp1621.github.io
- Supply chain security for Go, Part 3: Shifting leftsecurity.googleblog.com
- Supply chain security for the 0.001% and why it won't catch onblog.viraptor.info
- Supply Chain Security is FUBAR - A Proposal for GitHubpulse.latio.tech
- Supply-Chain Attacks Cluster: 230,000 Advisories, Five Patternsmsuiche.com
- supply-chain-monitor - LLM-based monitoring of top PyPI and npm packages for compromisegithub.com
- Tal Be'ery on the Safe wallet supply-chain hack behind the Bybit breachx.com
- TanStack npm supply-chain compromise advisory - 42 packages exfiltrating cloud credentials and SSH keysx.com
- Taxonomy of Attacks on Open-Source Software Supply Chainsarxiv.org
- TeamPCP - supply chain campaign breach trackerteampcp.cyberdigest.international
- TeamPCP Defaces Aqua Security's Internal GitHub Org - 44 repos exposedopensourcemalware.com
- TeamPCP Hijacks LiteLLM PyPI Package with Credential Stealerlinkedin.com
- TeamPCP Supply Chain Campaign - Incident Timeline and IOCsramimac.me
- Techies vs spies: the xz backdoor debatelcamtuf.substack.com
- The Case Against Automatic Dependency Updatesbeny23.github.io
- The Holiday Whisper: Shai-Hulud 3.0 npm worm variantsnyk.io
- The massive bug at the heart of the npm ecosystemblog.vlt.sh
- The Monsters in Your Build Cache - GitHub Actions Cache Poisoningadnanthekhan.com
- The Russian Open Source Project That We Can't Live Withouthuntedlabs.com
- The Snake is in the Grass - Finding Malicious PyPI Packages in the Wild - slidesdocs.google.com
- The sorry state of skill distributionblog.trailofbits.com
- The supply chain attack nobody is talking about: skill.md is an unsigned binarymoltbook.com
- Third-Party GitHub Actions: Effects of an Opt-Out Permission Modelpaloaltonetworks.com
- Thomas Roccia's attack-flow diagram of the 3CX supply chain attackx.com
- Thomas Roccia's one-page visual analysis of the XZ backdoor attackinfosec.exchange
- Toptal's GitHub Organization Hijacked - 10 Malicious Packages Publishedsocket.dev
- Trivy security incident 2026-03-01 - GitHub Actions supply chain compromisegithub.com
- Trivy security incident 2026-03-19 - malicious Trivy, trivy-action and setup-trivy releases stole CI credentialsgithub.com
- Trivy v0.69.4 binary supply-chain compromise: discussion with IoCs after incident thread was deletedgithub.com
- Trusted publishing for npm packagesdocs.npmjs.com
- Turn Dependabot Offwords.filippo.io
- Turning Dependency Confusion Research into a Profitable Stacksl4x0.medium.com
- undelete - recover packages deleted from NPM and PyPInpmjs.com
- Understanding and Re-Creating the tj-actions/changed-files Supply Chain Attackpulse.latio.tech
- Upcoming breaking changes for npm v12github.blog
- Using the determineversion API to find C/C++ vulnerabilitiesosv.dev
- uv Wants to Secure Your CLI Toolspydevtools.com
- vault-backdoored - antitree's backdoored fork of HashiCorp Vaultgithub.com
- Visual Studio Private Marketplace README - self-hosted extension marketplace for VS Codegithub.com
- VPChecker - vulnerability triage using code reachability, Supply Chain Reaction paper artifactsgithub.com
- VS Code issue: minimumReleaseAge setting to mitigate supply chain attacks on extensionsgithub.com
- VSMEx - VS Code Malicious Extensions Datasetgithub.com
- VSXSentry Guard - auto-block and remove malicious VS Code extensionsmarketplace.visualstudio.com
- Vulnerability and malware checks in uvastral.sh
- vx-underground on a malicious Cursor AI VS Code extension campaign targeting crypto holdersx.com
- Walshy on building a package registry gateway with version cooldowns after the TanStack compromisex.com
- Watching xz unfold from afarconnortumbleson.com
- Weaponizing Dependabot: Pwn Request at its Finestboostsecurity.io
- What Gets Measured Gets Managed: Mitigating Supply Chain Attacks with a Link Integrity Management Systemarxiv.org
- What the fork? Imposter commits in GitHub Actions and CI/CDchainguard.dev
- What's coming to our GitHub Actions 2026 security roadmapgithub.blog
- What's new in SLSA v1.0slsa.dev
- Wiz: GitHub Actions Security Part 1 - Threat Model, Attacks and Defenseswiz.io
- Wolves in the Repository: A Software Engineering Analysis of the XZ Utils Supply Chain Attackarxiv.org
- Worse than SolarWinds: Three Steps to Hack Blockchains, GitHub, and ML through GitHub Actionsjohnstawinski.com
- WTFpkg - catalog of package manager attack techniques across apt, pip, npm, RubyGems and Cargo0xv1n.github.io
- XZ Backdoor: Times, damned times, and scamsrheaeve.substack.com
- Xz format inadequate for long-term archivingnongnu.org
- xz Utils backdoor: malicious code in widely used Linux utility targets encrypted SSH connectionsarstechnica.com
- xz-utils backdoor situation - CVE-2024-3094gist.github.com
- xz/liblzma: Bash-stage Obfuscation Explainedgynvael.coldwind.pl?lang=en&id=782
- xzbot - xz backdoor exploit demo and honeypotgithub.com
- zizmor would have caught the Ultralytics workflow vulnerabilityblog.yossarian.net