software supply chain
"SBOMs describe what ends up in a piece of software, not how it got there. That distinction matters because..."
The malicious code creates a 'cascading compromise effect' into dependent ecosystems across npm's registry.
The malware "weaponized AI CLI tools (including Claude, Gemini, and q) to aid in reconnaissance and data exfiltration"
Google's new open source platform will shield popular dependencies with automations and data visibility tools.