DEV Community

# supplychainattack

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Attempt to stop npm postinstall scripts from stealing your secrets

Attempt to stop npm postinstall scripts from stealing your secrets

1
Comments
4 min read
11 Months Undetected: Inside a Silent Data Exfiltration Through a Trusted Vendor's Remote-Access Tool

11 Months Undetected: Inside a Silent Data Exfiltration Through a Trusted Vendor's Remote-Access Tool

Comments
5 min read
Identity Continuity Failure in WordPress Plugin Supply Chain Compromise

Identity Continuity Failure in WordPress Plugin Supply Chain Compromise

Comments
2 min read
Axios Compromise: What Actually Happened

Axios Compromise: What Actually Happened

Comments
4 min read
Malicious axios Update Exploits Dependency Trust Model

Malicious axios Update Exploits Dependency Trust Model

Comments
3 min read
The Real Failure in the axios npm Compromise Wasn't Code - It Was Trust

The Real Failure in the axios npm Compromise Wasn't Code - It Was Trust

Comments
3 min read
The Axios Supply Chain Attack Explained — npm's Biggest Security Breach in 2026

The Axios Supply Chain Attack Explained — npm's Biggest Security Breach in 2026

Comments
16 min read
Claude Code Source Leak: How One Packaging Mistake Created a Hacker Feeding Frenzy

Claude Code Source Leak: How One Packaging Mistake Created a Hacker Feeding Frenzy

Comments
6 min read
NPM Supply Chain Attacks in 2026: Why Libraries Like Axios Are Prime Targets [Guide]

NPM Supply Chain Attacks in 2026: Why Libraries Like Axios Are Prime Targets [Guide]

Comments
7 min read
Critical Alert: Axios NPM Package Compromised in Supply Chain Attack

Critical Alert: Axios NPM Package Compromised in Supply Chain Attack

Comments
2 min read
The LiteLLM Supply Chain Attack: Why Vibe Coders Are the Most Exposed

The LiteLLM Supply Chain Attack: Why Vibe Coders Are the Most Exposed

Comments
3 min read
Glassworm Is Back: The Invisible Unicode Attack Hiding in Your Code

Glassworm Is Back: The Invisible Unicode Attack Hiding in Your Code

Comments
7 min read
Stryker's Wiper Attack Exposes Cloud Management's Achilles Heel

Stryker's Wiper Attack Exposes Cloud Management's Achilles Heel

1
Comments
7 min read
Compromised GitHub PAT Used to Publish Malicious Trivy VSCode Extension: Mitigation Steps Outlined

Compromised GitHub PAT Used to Publish Malicious Trivy VSCode Extension: Mitigation Steps Outlined

1
Comments
7 min read
Supply Chain Attacks: How One Package Steals All Your Credentials

Supply Chain Attacks: How One Package Steals All Your Credentials

Comments
5 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.