software supply chain
One poisoned extension. One trusted developer. Goodbye, private repositories. Claude Code configurations being targeted.
"If an attacker can pollute Object.prototype via any other library in the stack (e.g., qs, minimist, ini, body-parser), Axios will automatically..."
“This is among the most operationally sophisticated supply chain attacks ever documented against a top-10 npm package."
The software supply chain startup is also now working with ISVs like Elastic and GitLab to harden their software as well as OSS.
"SBOMs describe what ends up in a piece of software, not how it got there. That distinction matters because..."
The malicious code creates a 'cascading compromise effect' into dependent ecosystems across npm's registry.