Supply Chain

Supply Chain

Software supply chain security covering npm vulnerabilities, dependency risks, SBOM implementation, package security, and protecting against supply chain attacks.
07
Apr
Developer desk with a "No Bad Days" sign, keyboard, coffee mug and monitor taken before the axios npm supply chain attack made March 31 2026 a very bad day

Axios NPM Supply Chain Attack (2026): What Happened and What to Do

On March 31, 2026, two malicious versions of the axios npm package were published using a compromised maintainer account. The
8 min read
04
Feb
Notepad++ update server compromise

Notepad++ Compromised for 6 Months: Check Your Version Now

Updated May 2026 Notepad++ update servers were compromised from June through December 2025 by a Chinese state-sponsored threat group. The
4 min read
15
Dec
Close-up of JavaScript code on a screen representing npm dependencies and supply chain security risks in modern software development

npm Security Risks: Most Vulnerable Packages in 2026

Updated April 2026 In 2025, attackers published 454,648 malicious npm packages. That’s nearly half a million in a
20 min read
04
Dec
React2Shell vulnerability concept showing React Server Components leaking into a remote shell execution (CVE-2025-55182)

CVE-2025-55182: React2Shell Detection and Fix Guide

UPDATE (Jan 1, 2026): RondoDox botnet now weaponizing React2Shell. Shadowserver reports 90,300 instances still vulnerable. Multiple nation-state actors actively
19 min read
02
Dec
Why npm audit fix Isn't Working

Why npm audit fix Isn't Working

You ran npm audit fix and it made no difference. Here is why, and what to do instead. This is
4 min read
30
Nov
Dark code editor displaying JavaScript import statements, representing the npm dependency ecosystem that supply chain attacks target

How Attackers Target npm Maintainer Accounts

April 2026 The registry trusts credentials, not identity. Detection time for npm maintainer account attacks has compressed from months to
19 min read
31
Oct
How the threat landscape will look in 2026

Four Threat Shifts That Will Define the 2026 Security Landscape

How the threat landscape shifted in 2025 and what to expect in 2026
6 min read
31
Oct
Gartner's 2025 Supply Chain Prediction: A Retrospective Look at What Actually Happened

Gartner's 2025 Supply Chain Prediction: A Retrospective Look at What Actually Happened

LinkedIn Post Copy Link In 2021, Gartner made a bold prediction: by 2025, 45% of organizations worldwide would experience attacks
6 min read
18
Sep
Poisoned Packages: Auditing the NPM Supply Chain

Poisoned Packages: Auditing the NPM Supply Chain

Navigating the rise of self-replicating worms and credential theft in the open-source world
2 min read