Skip to content
Topic

#Supply Chain Security

13 articles on Supply Chain Security — news, releases, guides and analysis from the SourceFeed engine.

Inside PinpinRAT: How APTs Hijack Developer Build Pipelines
Article 3d ago 5

Inside PinpinRAT: How APTs Hijack Developer Build Pipelines

A failed social engineering attack on a crates.io maintainer reveals highly stealthy local execution techniques.

Ji-ho Choi
AI Coding Assistants Turn Local Git Repos Into Cloud Exploits

AI Coding Assistants Turn Local Git Repos Into Cloud Exploits

Article · 3d ago2
The Cordyceps Exploits: Why Your CI/CD Pipelines Are Wide Open

The Cordyceps Exploits: Why Your CI/CD Pipelines Are Wide Open

Article · 5d ago0
Apple Absorbs Swift Package Index. Watch the Signing Plan.

Apple Absorbs Swift Package Index. Watch the Signing Plan.

News · 5d ago2
GitHub Hardens actions/checkout to Block Pwn Request Attacks

GitHub Hardens actions/checkout to Block Pwn Request Attacks

Article · 6d ago0
The GitHub Clone Farm That Beat VirusTotal

The GitHub Clone Farm That Beat VirusTotal

Article · 1w ago2
Arch's AUR Malware Sprawl Hits 1,579 Packages

Arch's AUR Malware Sprawl Hits 1,579 Packages

News · 2w ago6
Homebrew 6.0.0 Makes You Trust Your Taps

Homebrew 6.0.0 Makes You Trust Your Taps

Release · 2w ago7
npm v12 Is About to Stop Running Your Install Scripts — Here's What to Audit

npm v12 Is About to Stop Running Your Install Scripts — Here's What to Audit

News · 2w ago5
Miasma Worm Hits Microsoft Packages Twice in Weeks — and Your SLSA Provenance Won't Save You

Miasma Worm Hits Microsoft Packages Twice in Weeks — and Your SLSA Provenance Won't Save You

Article · 2w ago1
uv Gets Built-In Vulnerability and Malware Scanning

uv Gets Built-In Vulnerability and Malware Scanning

News · 3w ago1
Config Files That Run Code: The Supply Chain Blind Spot Nobody Is Auditing

Config Files That Run Code: The Supply Chain Blind Spot Nobody Is Auditing

Article · 3w ago0
Config Files That Run Code: The Supply Chain Blindspot You're Probably Not Auditing

Config Files That Run Code: The Supply Chain Blindspot You're Probably Not Auditing

Article · 3w ago0