software supply chain
Axios
|
Apr 13, 2026
"If an attacker can pollute Object.prototype via any other library in the stack (e.g., qs, minimist, ini, body-parser), Axios will automatically..."
Security
|
Mar 31, 2026
“This is among the most operationally sophisticated supply chain attacks ever documented against a top-10 npm package."
Chainguard
|
Mar 18, 2026
The software supply chain startup is also now working with ISVs like Elastic and GitLab to harden their software as well as OSS.
"SBOMs describe what ends up in a piece of software, not how it got there. That distinction matters because..."
The malicious code creates a 'cascading compromise effect' into dependent ecosystems across npm's registry.