Safeguard
Tag

supply-chain

Safeguard articles tagged "supply-chain" — guides, analysis, and best practices for software supply chain and application security.

859 articles

Agent Security

MCPoison (CVE-2025-54136): How Cursor's Trust Model Failed Open

Check Point Research showed Cursor bound trust to MCP entry names, not contents. A swap-after-approval gave attackers persistent RCE on engineers' laptops.

Jun 2, 20266 min read
AI Security

Claude Code Security: A Practical Guide for Teams Adopting AI Coding Agents

Claude Code can read your repo, run commands, and edit files — which is exactly why it needs the same security engineering as any privileged developer tool. Here's a practical hardening guide.

Jun 2, 20265 min read
DevSecOps

Is Node.js Safe? A Security Guide

Node.js itself is safe when kept current and configured well. Most real risk lives in your dependencies and your code, not the runtime.

Jun 2, 20265 min read
Open Source

Is react-spinners Safe? A Supply Chain Look at the npm Package

react-spinners is a popular zero-dependency loading component library for React. Here is an honest look at what it is and how to keep small npm dependencies safe.

May 30, 20265 min read
Threat Intelligence

ESET's May 2026 APT Report: Oil Shipments, Drone Makers, and a Poisoned npm Library

ESET's APT Activity Report (May 28, 2026) maps China-, North Korea-, Russia-, and Iran-aligned operations from October 2025 to March 2026 — including BlueNoroff's compromise of the axios npm package, a textbook supply-chain espionage event.

May 28, 202610 min read
Open Source

babel-jest: What It Does and How to Keep Your Test Toolchain Safe

babel-jest npm sits in almost every Jest install, quietly transforming your code before tests run. Here is what it does and why test toolchains deserve supply chain attention.

May 27, 20266 min read
Open Source

Archiver npm: A Security Review and Safe-Usage Guide

The archiver npm package builds zip and tar streams cleanly, but the real risks are on the extraction side and in its dependency tree. Here is how to use it safely.

May 25, 20265 min read
Open Source Security

PyPI's aliyun-ai-labs Campaign: Three Packages, One Targeted Region

Three PyPI packages impersonating Alibaba's AI Labs SDK exfiltrated .gitconfig data from developer machines in a regionally targeted 2025 espionage campaign.

May 24, 20266 min read
Supply Chain Attacks

Megalodon: 5,561 GitHub Repos Backdoored via Injected Actions Workflows (May 2026)

In a six-hour window on May 18, 2026, an automated campaign pushed malicious GitHub Actions workflows into 5,561 repositories using credentials harvested by infostealers. We break down the attack chain, the workflow_dispatch dormancy trick, and CI detection.

May 23, 202612 min read
Industry

in-toto Graduates from CNCF: Attestation Bundles and the v1 Layer

in-toto reached CNCF graduation in April 2025 and shipped a major attestation framework release. We walk through the bundle layer, resource descriptors, and what producers should adopt.

May 22, 20267 min read
AI Security

AI Code Detector: How It Works and Where It Fails

An AI code detector estimates whether source code was machine-generated. Here is how these tools work, why they misfire, and where security teams should and should not rely on them.

May 22, 20266 min read
Open Source

The npm figlet Package: A Security Review and Safe Usage Guide

The npm figlet package turns text into ASCII art and is downloaded well over a million times a week. Here is what it does, how to use it, and how to treat even a small utility as part of your supply chain.

May 22, 20265 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

supply-chain (Page 7) — Safeguard Blog