supply-chain-attack
Safeguard articles tagged "supply-chain-attack" — guides, analysis, and best practices for software supply chain and application security.
25 articles
The SolarWinds Orion Supply Chain Attack: What Actually Happened
A factual summary of the 2020 SolarWinds Orion compromise, in which attackers inserted malicious code into a legitimate software update, and what it means for build-pipeline integrity.
DAEMON Tools Lite's Official Installers Were Trojanized and Signed With a Real Certificate
A supply-chain compromise of AVB Disc Soft's own build infrastructure distributed digitally-signed, trojanized DAEMON Tools Lite installers from the vendor's legitimate website for nearly a month.
Two Billion Installs in an Afternoon: The keyv and cacheable npm Worm
On 4 August 2026, one compromised GitHub account seeded a self-propagating npm worm across 444 package names. The packages were caching utilities nobody thinks about — which is why it worked.
Your Dependency Incident Runbook Assumes a Fixed List of Bad Packages
Most supply chain runbooks say: get the affected package list, search lockfiles, remediate. Against a worm that adds packages while you work, every one of those steps is wrong.
A Year Inside the Installer: QuickFox, FDMTP, and Targeted Supply Chain Patience
The trojanized QuickFox installer ran for roughly a year, fingerprinting each victim before deploying a backdoor. Selective targeting bought the dwell time and broke conventional detection.
Bring Your Own Runtime: Why the keyv Payload Downloaded Bun
The August 2026 npm worm did not run its second stage in Node. It downloaded a standalone Bun binary first — a choice that defeats a surprising amount of build-pipeline monitoring.
npm 12 Turned Install Scripts Off. The keyv Worm Used a preinstall Hook Anyway.
Install scripts have been off by default since npm 12 shipped in July 2026. Four weeks later a worm propagated through preinstall hooks. A default is not a control until you prove it is enforced.
The torchtriton Dependency Confusion Attack on PyTorch-Ni...
How a namespace gap on PyPI let a malicious "torchtriton" package hijack PyTorch-nightly installs for five days, and what it teaches about ML supply chain security.
The 'ctx' PyPI Package Hijack via Expired Maintainer Domain
In 2022, attackers bought an expired domain, reset a PyPI maintainer's email, and hijacked the ctx package to steal environment variables from unsuspecting installs.
The tj-actions/changed-files GitHub Action Supply Chain C...
CVE-2025-30066 exposed how a compromised tj-actions/changed-files GitHub Action leaked CI/CD secrets into build logs across 23,000+ repos. Timeline, impact, and fixes.
Polyfill.io supply chain attack
How a domain sale turned a trusted CDN into a malware vector for 100,000+ sites — and what the polyfill.io incident teaches defenders about third-party script risk.
3CX desktop app supply chain compromise
A breakdown of the 3CX supply chain compromise: how Lazarus-linked attackers poisoned a signed desktop build via a nested vendor attack chain.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.