Home > Topics > software supply chain attack

software supply chain attack

4 articles and related resources

// Articles
News 3 min read Aug 25, 2026

Keyv npm Package Compromise Exposes Millions to Credential Theft

The compromise of the widely-used npm package keyv in August 2026 exposed millions to potential credential theft, highlighting critical software supply chain vu

News 4 min read Jun 6, 2026

NCSC Warns of Escalating Software Supply Chain Attacks Targeting Open Source Dependencies

The UK's NCSC warns of a surge in software supply chain attacks targeting open source dependencies, urging organizations to strengthen their security practices.

News 5 min read Jun 4, 2026

NCSC Warns of Rising Software Supply Chain Attacks Exploiting Open Source Dependencies

The NCSC warns of escalating software supply chain attacks exploiting open source dependencies, urging organizations to enhance security measures.

News 4 min read May 19, 2026

Malicious npm Package Compromises Multiple Production Deployments

A 42-line npm package was exploited to infiltrate multiple production environments, highlighting critical supply chain vulnerabilities.

News 5 min read May 16, 2026

Mini Shai-Hulud Campaign Targets Mistral AI and TanStack Packages

The 'Mini Shai-Hulud' campaign compromised Mistral AI and Tan ... , exposing sensitive credentials and highlighting software supply chain vulnerabilities.

News 3 min read Mar 24, 2026

New Research Unveils 'Java-Class-Hijack' Supply Chain Attack

Researchers unveil 'Java-Class-Hijack,' a novel supply chain attack exploiting Java's dependency resolution and classloading, posing significant risks to applic