supply-chain
Safeguard articles tagged "supply-chain" — guides, analysis, and best practices for software supply chain and application security.
859 articles
MCPoison (CVE-2025-54136): How Cursor's Trust Model Failed Open
Check Point Research showed Cursor bound trust to MCP entry names, not contents. A swap-after-approval gave attackers persistent RCE on engineers' laptops.
Claude Code Security: A Practical Guide for Teams Adopting AI Coding Agents
Claude Code can read your repo, run commands, and edit files — which is exactly why it needs the same security engineering as any privileged developer tool. Here's a practical hardening guide.
Is Node.js Safe? A Security Guide
Node.js itself is safe when kept current and configured well. Most real risk lives in your dependencies and your code, not the runtime.
Is react-spinners Safe? A Supply Chain Look at the npm Package
react-spinners is a popular zero-dependency loading component library for React. Here is an honest look at what it is and how to keep small npm dependencies safe.
ESET's May 2026 APT Report: Oil Shipments, Drone Makers, and a Poisoned npm Library
ESET's APT Activity Report (May 28, 2026) maps China-, North Korea-, Russia-, and Iran-aligned operations from October 2025 to March 2026 — including BlueNoroff's compromise of the axios npm package, a textbook supply-chain espionage event.
babel-jest: What It Does and How to Keep Your Test Toolchain Safe
babel-jest npm sits in almost every Jest install, quietly transforming your code before tests run. Here is what it does and why test toolchains deserve supply chain attention.
Archiver npm: A Security Review and Safe-Usage Guide
The archiver npm package builds zip and tar streams cleanly, but the real risks are on the extraction side and in its dependency tree. Here is how to use it safely.
PyPI's aliyun-ai-labs Campaign: Three Packages, One Targeted Region
Three PyPI packages impersonating Alibaba's AI Labs SDK exfiltrated .gitconfig data from developer machines in a regionally targeted 2025 espionage campaign.
Megalodon: 5,561 GitHub Repos Backdoored via Injected Actions Workflows (May 2026)
In a six-hour window on May 18, 2026, an automated campaign pushed malicious GitHub Actions workflows into 5,561 repositories using credentials harvested by infostealers. We break down the attack chain, the workflow_dispatch dormancy trick, and CI detection.
in-toto Graduates from CNCF: Attestation Bundles and the v1 Layer
in-toto reached CNCF graduation in April 2025 and shipped a major attestation framework release. We walk through the bundle layer, resource descriptors, and what producers should adopt.
AI Code Detector: How It Works and Where It Fails
An AI code detector estimates whether source code was machine-generated. Here is how these tools work, why they misfire, and where security teams should and should not rely on them.
The npm figlet Package: A Security Review and Safe Usage Guide
The npm figlet package turns text into ASCII art and is downloaded well over a million times a week. Here is what it does, how to use it, and how to treat even a small utility as part of your supply chain.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.