malware
Safeguard articles tagged "malware" — guides, analysis, and best practices for software supply chain and application security.
42 articles
PyPI Malicious Packages 2025: Python's Growing Supply Chain Problem
PyPI faced a surge of malicious package uploads in early 2025, targeting data science, AI/ML, and cloud development workflows. Here's the full picture.
Malicious Code Meaning: A Practical Definition for Developers
Malicious code is any software written to damage, disrupt, or gain unauthorized access to a system. Here is what the term actually covers and how it reaches your stack.
What Is Malicious Code in Cyber Security? Types, Detection, and Defense
Malicious code is any software written to harm a system or its users. Here is how the main families work, where they hide in modern supply chains, and how to catch them.
What is Malware
Malware now hides in open source packages and CI pipelines, not just email attachments. Here's what it is, how it spreads, and how to catch it early.
Define Malicious Code: Types, Examples, and Defenses
To define malicious code: it's any software or script written to damage, disrupt, or gain unauthorized access to a system. Here's the full taxonomy and how to defend against each type.
How Can Malicious Code Do Damage? A Practical Security Guide
Malicious code does damage by abusing the permissions of the process it runs in, then spreading, stealing, or destroying. Here is how each mechanism works and how to blunt it.
cross-env and the crossenv Typosquat: A Supply Chain Case Study
In 2017, a malicious crossenv package on npm stole environment variables from developers who mistyped cross-env. The incident is still the cleanest case study in typosquatting we have.
Which of the Following Is an Example of Malicious Code?
Viruses, worms, trojans, ransomware, spyware, and logic bombs are all examples of malicious code. Here is how to tell them apart and defend against each.
How Does Malicious Code Spread? A Practical Security Guide
Malicious code spreads through the channels people already trust: email attachments, infected downloads, removable media, compromised websites, and increasingly the software supply chain itself.
VS Code Marketplace Malware Campaigns in 2025
A senior engineer's review of the 2025 VS Code Marketplace malware wave, including typosquats, trojanized themes, and extensions that stole npm tokens at scale.
Office Document Macro Security: The Attack Vector That Will Not Die
Microsoft disabled macros by default in 2022. Attackers adapted. The macro threat has evolved, not disappeared.
PyPI Supply Chain Attacks: Q1 2024 Roundup
Q1 2024 brought typosquats, stealer campaigns, and a week-long new-user freeze on PyPI. Here is what the attacks looked like and how to defend.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.