account-takeover
Safeguard articles tagged "account-takeover" — guides, analysis, and best practices for software supply chain and application security.
21 articles
Account Linking by Email Match Trusts a Claim, Not a Verification
Continue with Google links to the matching existing account by email address. That is correct when the identity provider genuinely verified the email. Some providers make verification optional, and not every system checks which claim it is reading.
Which of Your Second Factors Can Be Relayed by Someone in the Middle
A code read off a screen and typed into a page can be typed into the wrong page. A key bound to an origin cannot produce anything usable for a site that is not yours. That is the whole distinction.
Domain Verification Is the Root of Trust for Your Enterprise Tier
Claiming a domain routes new signups, enforces sign-on and can absorb existing accounts. Every control that follows inherits whatever confidence that one check produced.
Account Recovery Is the Weakest Authentication You Have
You require strong passwords and enforce MFA, then built a flow that lets someone with inbox access bypass all of it. Recovery exists to let in someone who cannot satisfy the normal requirements, so every control above it is capped by how well it is built.
ua-parser-js (2021): An npm Account Takeover With Millions of Weekly Downloads
A factual account of the October 2021 ua-parser-js compromise, in which an attacker hijacked the maintainer npm account and published versions containing cryptominer and credential-stealing malware.
Nobody Is Exploiting Your Dependencies. They Are Logging Into Them.
keyv, Mastra, Nx, AsyncAPI, jscrambler. Five of 2026's largest supply chain incidents, and not one involved a software vulnerability. The exploited weakness every time was a maintainer account.
CocoaPods Trunk Server Email Verification Bypass Enabling...
CVE-2024-38367 let attackers bypass email verification on the CocoaPods trunk server to take over pod owner accounts, threatening the iOS supply chain. Here's the impact and fix.
RubyGems.org domain takeover risk report
RubyGems.org hasn't adopted the domain-resurrection defenses PyPI rolled out in 2025 — leaving a proven account-takeover technique open across the Ruby ecosystem.
Compromised NuGet author accounts
NuGet maintainer accounts are the .NET supply chain's weakest link. Here's why account takeover beats typosquatting, and how to detect it before a CVE exists.
lottie-player npm supply chain compromise
A phishing-driven npm token takeover pushed a crypto wallet drainer into lottie-player, hitting 94K weekly downloads before LottieFiles shipped a fix.
Anatomy of an npm maintainer account takeover
A single phishing email hit eslint-config-prettier's ~30M weekly downloads in July 2025 — no code compromise needed, just a stolen npm login.
Anatomy of a PyPI Compromise: How durabletask Got Hijacked in 35 Minutes
Three malicious durabletask releases hit PyPI in a 35-minute window in May 2026 — a maintainer-token theft, not a code review failure.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.