supply-chain-attack
Safeguard articles tagged "supply-chain-attack" — guides, analysis, and best practices for software supply chain and application security.
31 articles
Two Billion Installs in an Afternoon: The keyv and cacheable npm Worm
On 4 August 2026, one compromised GitHub account seeded a self-propagating npm worm across 444 package names. The packages were caching utilities nobody thinks about — which is why it worked.
Your Dependency Incident Runbook Assumes a Fixed List of Bad Packages
Most supply chain runbooks say: get the affected package list, search lockfiles, remediate. Against a worm that adds packages while you work, every one of those steps is wrong.
A Year Inside the Installer: QuickFox, FDMTP, and Targeted Supply Chain Patience
The trojanized QuickFox installer ran for roughly a year, fingerprinting each victim before deploying a backdoor. Selective targeting bought the dwell time and broke conventional detection.
Bring Your Own Runtime: Why the keyv Payload Downloaded Bun
The August 2026 npm worm did not run its second stage in Node. It downloaded a standalone Bun binary first — a choice that defeats a surprising amount of build-pipeline monitoring.
npm 12 Turned Install Scripts Off. The keyv Worm Used a preinstall Hook Anyway.
Install scripts have been off by default since npm 12 shipped in July 2026. Four weeks later a worm propagated through preinstall hooks. A default is not a control until you prove it is enforced.
The torchtriton Dependency Confusion Attack on PyTorch-Ni...
How a namespace gap on PyPI let a malicious "torchtriton" package hijack PyTorch-nightly installs for five days, and what it teaches about ML supply chain security.
The 'ctx' PyPI Package Hijack via Expired Maintainer Domain
In 2022, attackers bought an expired domain, reset a PyPI maintainer's email, and hijacked the ctx package to steal environment variables from unsuspecting installs.
The tj-actions/changed-files GitHub Action Supply Chain C...
CVE-2025-30066 exposed how a compromised tj-actions/changed-files GitHub Action leaked CI/CD secrets into build logs across 23,000+ repos. Timeline, impact, and fixes.
Polyfill.io supply chain attack
How a domain sale turned a trusted CDN into a malware vector for 100,000+ sites — and what the polyfill.io incident teaches defenders about third-party script risk.
3CX desktop app supply chain compromise
A breakdown of the 3CX supply chain compromise: how Lazarus-linked attackers poisoned a signed desktop build via a nested vendor attack chain.
Lessons from the 3CX Attack: The First Supply Chain Attack Caused by Another
3CX shipped a trojanized version of its own softphone through official updates in 2023 — because an employee installed compromised trading software. Here is the cascade, and its lessons.
Lessons from the Codecov Breach: When Your CI Secrets Walk Out the Door
For two months in 2021, Codecov's Bash Uploader quietly exfiltrated CI environment variables. Here is how a single trusted script became a mass credential-harvesting operation.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.