Safeguard
Tag

malware

Safeguard articles tagged "malware" — guides, analysis, and best practices for software supply chain and application security.

38 articles

Supply Chain Security

eBPF Rootkits Go Mainstream: Inside IronWorm and the Kernel-Level Turn in Supply Chain Malware

IronWorm shipped a kernel-level eBPF rootkit inside dozens of npm packages, hiding the very processes your security tools rely on seeing. Here is what changed, and how to detect kernel-level supply chain malware before it blinds you.

Jun 16, 20267 min read
Security

What Is the Definition of Malicious Code?

Malicious code is any software or script written to damage, disrupt, or gain unauthorized access to a system. Here is a precise definition and the main categories.

Apr 28, 20266 min read
Security

Malicious Code Meaning: A Practical Definition for Developers

Malicious code is any software written to damage, disrupt, or gain unauthorized access to a system. Here is what the term actually covers and how it reaches your stack.

Apr 6, 20266 min read
Security

What Is Malicious Code in Cyber Security? Types, Detection, and Defense

Malicious code is any software written to harm a system or its users. Here is how the main families work, where they hide in modern supply chains, and how to catch them.

Mar 27, 20267 min read
Vulnerability Analysis

What is Malware

Malware now hides in open source packages and CI pipelines, not just email attachments. Here's what it is, how it spreads, and how to catch it early.

Mar 25, 20267 min read
Security

Define Malicious Code: Types, Examples, and Defenses

To define malicious code: it's any software or script written to damage, disrupt, or gain unauthorized access to a system. Here's the full taxonomy and how to defend against each type.

Mar 25, 20266 min read
Security

How Can Malicious Code Do Damage? A Practical Security Guide

Malicious code does damage by abusing the permissions of the process it runs in, then spreading, stealing, or destroying. Here is how each mechanism works and how to blunt it.

Mar 22, 20266 min read
Supply Chain

cross-env and the crossenv Typosquat: A Supply Chain Case Study

In 2017, a malicious crossenv package on npm stole environment variables from developers who mistyped cross-env. The incident is still the cleanest case study in typosquatting we have.

Mar 21, 20267 min read
Security

Which of the Following Is an Example of Malicious Code?

Viruses, worms, trojans, ransomware, spyware, and logic bombs are all examples of malicious code. Here is how to tell them apart and defend against each.

Mar 21, 20266 min read
Security

How Does Malicious Code Spread? A Practical Security Guide

Malicious code spreads through the channels people already trust: email attachments, infected downloads, removable media, compromised websites, and increasingly the software supply chain itself.

Mar 20, 20266 min read
Supply Chain Attacks

VS Code Marketplace Malware Campaigns in 2025

A senior engineer's review of the 2025 VS Code Marketplace malware wave, including typosquats, trojanized themes, and extensions that stole npm tokens at scale.

Mar 11, 20267 min read
Open Source Security

PyPI Supply Chain Attacks: Q1 2024 Roundup

Q1 2024 brought typosquats, stealer campaigns, and a week-long new-user freeze on PyPI. Here is what the attacks looked like and how to defend.

Feb 23, 20265 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.