Safeguard
Tag

supply-chain-attack

Safeguard articles tagged "supply-chain-attack" — guides, analysis, and best practices for software supply chain and application security.

31 articles

Software Supply Chain Security

Two Billion Installs in an Afternoon: The keyv and cacheable npm Worm

On 4 August 2026, one compromised GitHub account seeded a self-propagating npm worm across 444 package names. The packages were caching utilities nobody thinks about — which is why it worked.

Aug 10, 20266 min read
Incident Analysis

Your Dependency Incident Runbook Assumes a Fixed List of Bad Packages

Most supply chain runbooks say: get the affected package list, search lockfiles, remediate. Against a worm that adds packages while you work, every one of those steps is wrong.

Aug 9, 20267 min read
Supply Chain Attacks

A Year Inside the Installer: QuickFox, FDMTP, and Targeted Supply Chain Patience

The trojanized QuickFox installer ran for roughly a year, fingerprinting each victim before deploying a backdoor. Selective targeting bought the dwell time and broke conventional detection.

Aug 8, 20266 min read
Threat Intelligence

Bring Your Own Runtime: Why the keyv Payload Downloaded Bun

The August 2026 npm worm did not run its second stage in Node. It downloaded a standalone Bun binary first — a choice that defeats a surprising amount of build-pipeline monitoring.

Aug 6, 20266 min read
Open Source Security

npm 12 Turned Install Scripts Off. The keyv Worm Used a preinstall Hook Anyway.

Install scripts have been off by default since npm 12 shipped in July 2026. Four weeks later a worm propagated through preinstall hooks. A default is not a control until you prove it is enforced.

Aug 5, 20266 min read
Open Source Security

The torchtriton Dependency Confusion Attack on PyTorch-Ni...

How a namespace gap on PyPI let a malicious "torchtriton" package hijack PyTorch-nightly installs for five days, and what it teaches about ML supply chain security.

Jul 29, 20267 min read
Open Source Security

The 'ctx' PyPI Package Hijack via Expired Maintainer Domain

In 2022, attackers bought an expired domain, reset a PyPI maintainer's email, and hijacked the ctx package to steal environment variables from unsuspecting installs.

Jul 28, 20267 min read
DevSecOps

The tj-actions/changed-files GitHub Action Supply Chain C...

CVE-2025-30066 exposed how a compromised tj-actions/changed-files GitHub Action leaked CI/CD secrets into build logs across 23,000+ repos. Timeline, impact, and fixes.

Jul 27, 20268 min read
Incident Analysis

Polyfill.io supply chain attack

How a domain sale turned a trusted CDN into a malware vector for 100,000+ sites — and what the polyfill.io incident teaches defenders about third-party script risk.

Jul 13, 20267 min read
Incident Analysis

3CX desktop app supply chain compromise

A breakdown of the 3CX supply chain compromise: how Lazarus-linked attackers poisoned a signed desktop build via a nested vendor attack chain.

Jul 12, 20267 min read
Threat Research

Lessons from the 3CX Attack: The First Supply Chain Attack Caused by Another

3CX shipped a trojanized version of its own softphone through official updates in 2023 — because an employee installed compromised trading software. Here is the cascade, and its lessons.

Jul 5, 20266 min read
Threat Research

Lessons from the Codecov Breach: When Your CI Secrets Walk Out the Door

For two months in 2021, Codecov's Bash Uploader quietly exfiltrated CI environment variables. Here is how a single trusted script became a mass credential-harvesting operation.

Jul 4, 20266 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

supply-chain-attack — Safeguard Blog