# chainguard libraries

Published articles for chainguard libraries.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Chainguard Libraries now available on AWS Security Hub Extended

DevFeed: [Chainguard Libraries now available on AWS Security Hub Extended](<https://devfeed.tech/articles/chainguard-libraries-now-available-on-aws-security-hub-extended-12969.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-libraries-now-available-on-aws-security-hub-extended>)

Published: 2026-08-04T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [AWS Security Hub](<https://devfeed.tech/topics/aws-security-hub.md>), [Security](<https://devfeed.tech/topics/security.md>), [software supply-chain attack](<https://devfeed.tech/topics/software-supply-chain-attack.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>)

Tags: [ai-coding](<https://devfeed.tech/tags/ai-coding.md>), [aws-security-hub](<https://devfeed.tech/tags/aws-security-hub.md>), [axios](<https://devfeed.tech/tags/axios.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [java](<https://devfeed.tech/tags/java.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [litellm](<https://devfeed.tech/tags/litellm.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mini-shai-hulud](<https://devfeed.tech/tags/mini-shai-hulud.md>), [npm](<https://devfeed.tech/tags/npm.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [python](<https://devfeed.tech/tags/python.md>), [redhat](<https://devfeed.tech/tags/redhat.md>), [redhat-cloud-services](<https://devfeed.tech/tags/redhat-cloud-services.md>), [security](<https://devfeed.tech/tags/security.md>), [shai-hulud](<https://devfeed.tech/tags/shai-hulud.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-attack](<https://devfeed.tech/tags/software-supply-chain-attack.md>), [telnyx](<https://devfeed.tech/tags/telnyx.md>)

### AI overview

Chainguard Libraries is now available through AWS Security Hub Extended's Supply Chain category. The article presents it as a malware-free catalog of Python, Java, and JavaScript dependencies intended to reduce reliance on public registries and help protect AWS workloads from software supply-chain attacks.

### Source excerpt

Chainguard Libraries is now available in AWS Security Hub Extended, delivering malware-resistant open source dependencies for AWS workloads.

## Booz Allen Hamilton signs enterprise license agreement with Chainguard

DevFeed: [Booz Allen Hamilton signs enterprise license agreement with Chainguard](<https://devfeed.tech/articles/booz-allen-hamilton-signs-enterprise-license-agreement-with-chainguard-12897.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/booz-allen-hamilton-signs-enterprise-license-agreement-with-chainguard>)

Published: 2026-07-21T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [ato](<https://devfeed.tech/tags/ato.md>), [authority-to-operate](<https://devfeed.tech/tags/authority-to-operate.md>), [booz-allen-hamilton](<https://devfeed.tech/tags/booz-allen-hamilton.md>), [booz-allen-hamilton-engineering](<https://devfeed.tech/tags/booz-allen-hamilton-engineering.md>), [booz-chainguard-partnership](<https://devfeed.tech/tags/booz-chainguard-partnership.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-booz](<https://devfeed.tech/tags/chainguard-booz.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [development](<https://devfeed.tech/tags/development.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [government](<https://devfeed.tech/tags/government.md>), [partner](<https://devfeed.tech/tags/partner.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [trust](<https://devfeed.tech/tags/trust.md>), [us](<https://devfeed.tech/tags/us.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Booz Allen Hamilton has signed an enterprise license agreement with Chainguard, giving more than 6,000 engineers access to Chainguard Containers and Chainguard Libraries across U.S. government programs. The agreement is intended to support secure-by-default software delivery, vulnerability remediation, compliance, and software supply chain requirements.

### Source excerpt

Booz Allen and Chainguard partner to help 6,000+ engineers deliver secure-by-default software across U.S. government programs.

## AsyncAPI supply chain compromise: npm packages backdoored via GitHub Actions "pwn request" (July 2026)

DevFeed: [AsyncAPI supply chain compromise: npm packages backdoored via GitHub Actions "pwn request" (July 2026)](<https://devfeed.tech/articles/asyncapi-supply-chain-compromise-npm-packages-backdoored-via-github-actions-pwn-request-july-2026-12890.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/asyncapi-supply-chain-compromise-npm-packages-backdoored-via-github-actions>)

Published: 2026-07-14T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [npm packages](<https://devfeed.tech/topics/npm-packages.md>), [AsyncAPI Specification](<https://devfeed.tech/topics/asyncapi.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Remote Access Trojan](<https://devfeed.tech/topics/remote-access-trojan.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>)

Tags: [asyncapi-supply-chain-attack](<https://devfeed.tech/tags/asyncapi-supply-chain-attack.md>), [chainguard-asyncapi](<https://devfeed.tech/tags/chainguard-asyncapi.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [ci](<https://devfeed.tech/tags/ci.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [github-actions-pwn-request](<https://devfeed.tech/tags/github-actions-pwn-request.md>), [malicious-packages](<https://devfeed.tech/tags/malicious-packages.md>), [malware](<https://devfeed.tech/tags/malware.md>), [miasma](<https://devfeed.tech/tags/miasma.md>), [npm](<https://devfeed.tech/tags/npm.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [personal-access-token](<https://devfeed.tech/tags/personal-access-token.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [pull-requests](<https://devfeed.tech/tags/pull-requests.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [tokens](<https://devfeed.tech/tags/tokens.md>)

### AI overview

The article analyzes a July 14, 2026 supply-chain compromise in which an attacker stole a privileged GitHub personal access token through a misconfigured GitHub Actions workflow and used it to publish five backdoored versions across four AsyncAPI npm packages. The malware activates when a library is loaded by a build or CI job and steals browser passwords, SSH keys, npm and GitHub tokens, cloud credentials, and cryptocurrency wallets while maintaining command-and-control access. It also explains why Chainguard customers were protected and recommends treating affected environments as compromised and rotating credentials.

### Source excerpt

A supply chain attack compromised AsyncAPI npm packages via GitHub Actions. See how Chainguard blocked the malicious releases by design.

## Expanding Athena

DevFeed: [Expanding Athena](<https://devfeed.tech/articles/expanding-athena-13034.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/expanding-athena>)

Published: 2026-07-07T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Frontier AI](<https://devfeed.tech/topics/frontier-ai.md>), [AI Models](<https://devfeed.tech/topics/ai-models.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>), [Parser](<https://devfeed.tech/topics/parser.md>), [Library](<https://devfeed.tech/topics/library.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [akrites](<https://devfeed.tech/tags/akrites.md>), [athena](<https://devfeed.tech/tags/athena.md>), [chainguard-clearinghouse](<https://devfeed.tech/tags/chainguard-clearinghouse.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [frontier-ai](<https://devfeed.tech/tags/frontier-ai.md>), [library](<https://devfeed.tech/tags/library.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [parsing](<https://devfeed.tech/tags/parsing.md>), [secure-open-source](<https://devfeed.tech/tags/secure-open-source.md>), [secure-oss](<https://devfeed.tech/tags/secure-oss.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard describes Athena, an industry coalition coordinating the discovery, remediation, protection, disclosure, and upstream fixing of vulnerabilities in open source software. The article reports that Athena has processed more than 40,000 vulnerabilities and emphasizes that frontier AI models can identify latent flaws and chain lower-severity bugs into serious attacks.

### Source excerpt

See how Athena is helping secure open source by coordinating AI-discovered vulnerabilities, partner protections, and upstream fixes at scale.

## Why Vulnerability Clearinghouses Alone Cannot Secure Open Source

DevFeed: [Why Vulnerability Clearinghouses Alone Cannot Secure Open Source](<https://devfeed.tech/articles/summer-of-clearinghouses-13244.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/summer-of-clearinghouses>)

Published: 2026-07-05T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [data](<https://devfeed.tech/topics/data.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>), [NVD](<https://devfeed.tech/topics/nvd.md>), [Unix](<https://devfeed.tech/topics/unix.md>)

Tags: [akrites](<https://devfeed.tech/tags/akrites.md>), [athena](<https://devfeed.tech/tags/athena.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [data](<https://devfeed.tech/tags/data.md>), [ibm-red-hat-project-lightwell](<https://devfeed.tech/tags/ibm-red-hat-project-lightwell.md>), [nvd](<https://devfeed.tech/tags/nvd.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [press-release](<https://devfeed.tech/tags/press-release.md>), [secure-open-source](<https://devfeed.tech/tags/secure-open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [security-research](<https://devfeed.tech/tags/security-research.md>), [vulnerability-clearinghouse](<https://devfeed.tech/tags/vulnerability-clearinghouse.md>), [vulnerability-data](<https://devfeed.tech/tags/vulnerability-data.md>)

### AI overview

The article argues that vulnerability clearinghouses are primarily pools of data and are not the most important part of securing open source. It emphasizes actuation--turning findings into fixes--along with trusted builds and secure-by-design software.

### Source excerpt

Clearinghouses alone won't secure open source. Learn why actuation, trusted builds, and secure-by-design software matter more than vulnerability data.

## The State of Trusted Open Source: June 2026

DevFeed: [The State of Trusted Open Source: June 2026](<https://devfeed.tech/articles/the-state-of-trusted-open-source-june-2026-13271.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-state-of-trusted-open-source-june-2026>)

Published: 2026-06-30T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Open Source](<https://devfeed.tech/topics/open-source.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [ai](<https://devfeed.tech/tags/ai.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-data](<https://devfeed.tech/tags/cve-data.md>), [cves](<https://devfeed.tech/tags/cves.md>), [data](<https://devfeed.tech/tags/data.md>), [dependency](<https://devfeed.tech/tags/dependency.md>), [java](<https://devfeed.tech/tags/java.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [nginx](<https://devfeed.tech/tags/nginx.md>), [node](<https://devfeed.tech/tags/node.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [python](<https://devfeed.tech/tags/python.md>), [report](<https://devfeed.tech/tags/report.md>), [security](<https://devfeed.tech/tags/security.md>), [software](<https://devfeed.tech/tags/software.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [state-of-trusted-open-source](<https://devfeed.tech/tags/state-of-trusted-open-source.md>), [trends](<https://devfeed.tech/tags/trends.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Chainguard's June 2026 report analyzes vulnerability data from more than 2,400 container image projects and 18,016 vulnerability instances observed from March through May 2026. It reports 886 distinct CVEs, with 63.1% of observed instances classified as high severity, and examines how AI-assisted development and security research are affecting software supply-chain risk.

### Source excerpt

AI is accelerating vulnerability discovery. Explore the latest trusted open source trends, dependency risks, and CVE insights from Chainguard's report.

## Chainguard Repository adds new policies, Chainguard Libraries for JavaScript is GA

DevFeed: [Chainguard Repository adds new policies, Chainguard Libraries for JavaScript is GA](<https://devfeed.tech/articles/chainguard-repository-adds-new-policies-chainguard-libraries-for-javascript-is-ga-12979.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-repository-adds-new-policies-chainguard-libraries-for-javascript-is-ga>)

Published: 2026-06-25T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard repository](<https://devfeed.tech/topics/chainguard-repository.md>), [chainguard libraries for javascript](<https://devfeed.tech/topics/chainguard-libraries-for-javascript.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-libraries-for-java](<https://devfeed.tech/tags/chainguard-libraries-for-java.md>), [chainguard-libraries-for-javascript](<https://devfeed.tech/tags/chainguard-libraries-for-javascript.md>), [chainguard-libraries-for-python](<https://devfeed.tech/tags/chainguard-libraries-for-python.md>), [chainguard-repo](<https://devfeed.tech/tags/chainguard-repo.md>), [chainguard-repository](<https://devfeed.tech/tags/chainguard-repository.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [libraries](<https://devfeed.tech/tags/libraries.md>), [malware](<https://devfeed.tech/tags/malware.md>), [malware-scanner](<https://devfeed.tech/tags/malware-scanner.md>), [policy](<https://devfeed.tech/tags/policy.md>), [visibility](<https://devfeed.tech/tags/visibility.md>)

### AI overview

Chainguard announces new malware and greyware scanning for additional artifact types, expanded policy controls, and new visibility features in Chainguard Repository. The article also announces general availability of Chainguard Libraries for JavaScript.

### Source excerpt

Chainguard Repository adds malware and greyware scanning, expanded policy controls, and visibility to secure AI-driven software supply chains.

## Fewer CVEs, more accurate findings: Wiz now scans Chainguard Libraries for Python and Java

DevFeed: [Fewer CVEs, more accurate findings: Wiz now scans Chainguard Libraries for Python and Java](<https://devfeed.tech/articles/fewer-cves-more-accurate-findings-wiz-now-scans-chainguard-libraries-for-python-and-java-13335.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/wiz-now-scans-chainguard-libraries-for-python-and-java>)

Published: 2026-06-25T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [chainguard libraries for python](<https://devfeed.tech/topics/chainguard-libraries-for-python.md>), [Java](<https://devfeed.tech/topics/java.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-libraries-for-java](<https://devfeed.tech/tags/chainguard-libraries-for-java.md>), [chainguard-libraries-for-python](<https://devfeed.tech/tags/chainguard-libraries-for-python.md>), [cves](<https://devfeed.tech/tags/cves.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [java](<https://devfeed.tech/tags/java.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [python](<https://devfeed.tech/tags/python.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [wiz](<https://devfeed.tech/tags/wiz.md>), [wiz-chainguard-libraries](<https://devfeed.tech/tags/wiz-chainguard-libraries.md>), [wiz-chainguard-scanner](<https://devfeed.tech/tags/wiz-chainguard-scanner.md>)

### AI overview

Wiz now scans Chainguard Libraries for Python and Java. The partnership combines source-built dependencies and backported fixes with Wiz's risk context and visibility, helping organizations assess vulnerabilities, prioritize remediation, and verify artifact provenance.

### Source excerpt

Wiz now scans Chainguard Libraries for Python and Java, combining trusted, source-built dependencies with risk-based visibility and remediation.

## Everything we announced during AI Readiness Innovation Week

DevFeed: [Everything we announced during AI Readiness Innovation Week](<https://devfeed.tech/articles/everything-we-announced-during-ai-readiness-innovation-week-13033.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/everything-we-announced-during-ai-readiness-innovation-week>)

Published: 2026-06-25T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [ai-coding](<https://devfeed.tech/topics/ai-coding.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Frontier AI](<https://devfeed.tech/topics/frontier-ai.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-readiness](<https://devfeed.tech/tags/ai-readiness.md>), [athena](<https://devfeed.tech/tags/athena.md>), [aws-kiro](<https://devfeed.tech/tags/aws-kiro.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cursor](<https://devfeed.tech/tags/cursor.md>), [frontier-ai-models](<https://devfeed.tech/tags/frontier-ai-models.md>), [gartner-magic-quadrant](<https://devfeed.tech/tags/gartner-magic-quadrant.md>), [github](<https://devfeed.tech/tags/github.md>), [innovation](<https://devfeed.tech/tags/innovation.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [speed](<https://devfeed.tech/tags/speed.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard summarizes announcements from AI Readiness Innovation Week, covering supply-chain security advances for containers, libraries, CI/CD pipelines, AI agent skills, IDE integrations, partnerships, and an industry coalition. The article highlights Athena, a coalition designed to coordinate defense against vulnerabilities discovered by frontier AI models.

### Source excerpt

Read about everything Chainguard announced during AI Readiness Innovation Week, including new features for Chainguard Libraries and Chainguard Containers.

## How Chainguard uses AI agents to enforce engineering standards across a monorepo

DevFeed: [How Chainguard uses AI agents to enforce engineering standards across a monorepo](<https://devfeed.tech/articles/this-shit-is-hard-how-ai-keeps-our-code-on-standard-13282.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/this-shit-is-hard-how-ai-keeps-our-code-on-standard>)

Published: 2026-06-24T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Bot](<https://devfeed.tech/topics/bot.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-agent-skills](<https://devfeed.tech/tags/chainguard-agent-skills.md>), [chainguard-agents](<https://devfeed.tech/tags/chainguard-agents.md>), [chainguard-ai](<https://devfeed.tech/tags/chainguard-ai.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-engineering](<https://devfeed.tech/tags/chainguard-engineering.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [ci](<https://devfeed.tech/tags/ci.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [github](<https://devfeed.tech/tags/github.md>), [policy](<https://devfeed.tech/tags/policy.md>), [pull-request](<https://devfeed.tech/tags/pull-request.md>), [workflow](<https://devfeed.tech/tags/workflow.md>)

### AI overview

Chainguard describes a system of specialized AI agents built on DriftlessAF that continuously checks code against machine-readable engineering standards, fixes drift, and supports CI repair. Over eight weeks, it opened more than 4,700 standards-fix pull requests; 75% judged low-risk were auto-merged when AI judgment agreed with deterministic checks.

### Source excerpt

Chainguard uses AI-powered agents to continuously enforce engineering standards, remediate drift, and keep codebases aligned at scale.

## Securing the AI coding ecosystem: Chainguard and the AI tools developers use

DevFeed: [Securing the AI coding ecosystem: Chainguard and the AI tools developers use](<https://devfeed.tech/articles/securing-the-ai-coding-ecosystem-chainguard-and-the-ai-tools-developers-use-13222.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/securing-the-ai-coding-ecosystem-chainguard-and-the-ai-tools-developers-use>)

Published: 2026-06-24T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Kiro](<https://devfeed.tech/topics/kiro.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>), [cursor](<https://devfeed.tech/topics/cursor.md>), [Security](<https://devfeed.tech/topics/security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [ai-coding](<https://devfeed.tech/tags/ai-coding.md>), [aws-kiro](<https://devfeed.tech/tags/aws-kiro.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-ai-tools](<https://devfeed.tech/tags/chainguard-ai-tools.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cursor](<https://devfeed.tech/tags/cursor.md>), [developers](<https://devfeed.tech/tags/developers.md>), [kiro](<https://devfeed.tech/tags/kiro.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>)

### AI overview

Chainguard argues that AI coding tools such as Kiro and Cursor need trusted sources for dependencies and container images. The article describes Chainguard Containers, Libraries, and a Kiro plugin intended to move projects from public registries to hardened supply-chain components.

### Source excerpt

Chainguard brings secure-by-default containers and libraries to AI coding tools like Kiro and Cursor, making trusted open source the default.

## Chainguard plug-in now available on Cursor Marketplace

DevFeed: [Chainguard plug-in now available on Cursor Marketplace](<https://devfeed.tech/articles/chainguard-plug-in-now-available-on-cursor-marketplace-12976.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-plug-in-now-available-on-cursor-marketplace>)

Published: 2026-06-24T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [cursor](<https://devfeed.tech/topics/cursor.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [ai-coding-agents](<https://devfeed.tech/tags/ai-coding-agents.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-cursor](<https://devfeed.tech/tags/chainguard-cursor.md>), [chainguard-cursor-marketplace](<https://devfeed.tech/tags/chainguard-cursor-marketplace.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cursor](<https://devfeed.tech/tags/cursor.md>), [cursor-chainguard-containers](<https://devfeed.tech/tags/cursor-chainguard-containers.md>), [cursor-chainguard-libraries](<https://devfeed.tech/tags/cursor-chainguard-libraries.md>), [libraries](<https://devfeed.tech/tags/libraries.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [plugin](<https://devfeed.tech/tags/plugin.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Chainguard has launched a plugin on the Cursor Marketplace that connects Cursor to Chainguard Containers, Chainguard Libraries, and the Chainguard Repository. The plugin is intended to make secure-by-default artifacts available in AI coding workflows and help agents remediate known vulnerabilities.

### Source excerpt

Connect Cursor to Chainguard in minutes and make secure, malware-resistant containers and libraries the default for AI-generated code.

## Chainguard Libraries for Java is now GA; CVE remediation beta available for sign up

DevFeed: [Chainguard Libraries for Java is now GA; CVE remediation beta available for sign up](<https://devfeed.tech/articles/chainguard-libraries-for-java-is-now-ga-cve-remediation-beta-available-for-sign-up-12966.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-libraries-for-java-is-now-ga-and-includes-cve-remediation>)

Published: 2026-06-23T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [Java](<https://devfeed.tech/topics/java.md>), [Spring Boot](<https://devfeed.tech/topics/spring-boot.md>), [Security](<https://devfeed.tech/topics/security.md>), [Back end](<https://devfeed.tech/topics/backend.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-libraries-for-java](<https://devfeed.tech/tags/chainguard-libraries-for-java.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [java](<https://devfeed.tech/tags/java.md>), [java-packages](<https://devfeed.tech/tags/java-packages.md>), [java-spring](<https://devfeed.tech/tags/java-spring.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [scanner](<https://devfeed.tech/tags/scanner.md>), [security](<https://devfeed.tech/tags/security.md>), [zero-cve-packages](<https://devfeed.tech/tags/zero-cve-packages.md>)

### AI overview

Chainguard Libraries for Java is generally available, and its CVE remediation capability is available in beta. The article describes backported fixes for critical and high-severity CVEs across the Spring Boot ecosystem, helping teams manage risks in pinned or legacy Java dependencies while planning upgrades.

### Source excerpt

Chainguard Libraries for Java is now GA, delivering CVE-remediated dependencies with SBOMs, provenance, and scanner-recognized fixes.

## Building a category: Chainguard named a Leader in the inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security

DevFeed: [Building a category: Chainguard named a Leader in the inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security](<https://devfeed.tech/articles/building-a-category-chainguard-named-a-leader-in-the-inaugural-gartner-magic-quadranttm-for-software-supply-chain-security-12901.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/building-a-category-chainguard-named-a-leader-in-the-inaugural-gartner-magic-quadrant-for-software-supply-chain-security>)

Published: 2026-06-22T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-gartner](<https://devfeed.tech/tags/chainguard-gartner.md>), [chainguard-gartner-mq](<https://devfeed.tech/tags/chainguard-gartner-mq.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [gartner](<https://devfeed.tech/tags/gartner.md>), [gartner-magic-quadrant](<https://devfeed.tech/tags/gartner-magic-quadrant.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [software-supply-chain-security-gartner](<https://devfeed.tech/tags/software-supply-chain-security-gartner.md>), [software-supply-chain-security-mq](<https://devfeed.tech/tags/software-supply-chain-security-mq.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

Chainguard's article discusses its recognition as a Leader in Gartner's inaugural Magic Quadrant for Software Supply Chain Security. It argues that accelerating vulnerability exploitation and AI-assisted development require prevention-oriented, secure-by-default supply chain security. The article highlights Chainguard Containers, which provides minimal container images rebuilt daily from source, with zero CVEs, SBOMs, and verifiable signatures, and briefly introduces Chainguard Libraries.

### Source excerpt

Gartner names Chainguard a Leader in Software Supply Chain Security, highlighting its secure-by-default approach and market vision.

## The Maintainer of Last Resort

DevFeed: [The Maintainer of Last Resort](<https://devfeed.tech/articles/the-maintainer-of-last-resort-13262.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-maintainer-of-last-resort>)

Published: 2026-06-22T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Open Source](<https://devfeed.tech/topics/open-source.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Software](<https://devfeed.tech/topics/software.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-open-source](<https://devfeed.tech/tags/chainguard-open-source.md>), [emertioss](<https://devfeed.tech/tags/emertioss.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-maintainer](<https://devfeed.tech/tags/open-source-maintainer.md>), [oss](<https://devfeed.tech/tags/oss.md>), [providers](<https://devfeed.tech/tags/providers.md>), [software](<https://devfeed.tech/tags/software.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard proposes a Maintainer of Last Resort as a neutral backstop for abandoned open source projects. The model would fork vulnerable packages, apply fixes, publish verifiable builds, and handle future vulnerability disclosures when upstream maintainers cannot respond in time.

### Source excerpt

Chainguard proposes a Maintainer of Last Resort to patch abandoned open source projects, publish trusted builds, and keep critical software secure.

## @mastra npm scope takeover: 143 packages backdoored via compromised contributor account

DevFeed: [@mastra npm scope takeover: 143 packages backdoored via compromised contributor account](<https://devfeed.tech/articles/mastra-npm-scope-takeover-143-packages-backdoored-via-compromised-contributor-account-13149.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/mastra-npm-scope-takeover-143-packages-backdoored-via-compromised-contributor-account>)

Published: 2026-06-17T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [npm](<https://devfeed.tech/topics/npm.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Remote Access Trojan](<https://devfeed.tech/topics/remote-access-trojan.md>), [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>), [C2](<https://devfeed.tech/topics/c2.md>)

Tags: [c2](<https://devfeed.tech/tags/c2.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-packages](<https://devfeed.tech/tags/chainguard-packages.md>), [command-and-control](<https://devfeed.tech/tags/command-and-control.md>), [crypto](<https://devfeed.tech/tags/crypto.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mastra](<https://devfeed.tech/tags/mastra.md>), [npm](<https://devfeed.tech/tags/npm.md>), [npm-takeover](<https://devfeed.tech/tags/npm-takeover.md>), [packages](<https://devfeed.tech/tags/packages.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [remote-access](<https://devfeed.tech/tags/remote-access.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [secure-packages](<https://devfeed.tech/tags/secure-packages.md>), [software-packages](<https://devfeed.tech/tags/software-packages.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [tls](<https://devfeed.tech/tags/tls.md>)

### AI overview

The article reports that an attacker used a compromised former contributor account to republish all 143 packages in the @mastra npm scope on June 17, 2026. The malicious versions could disable TLS verification, download a cryptocurrency wallet stealer and remote access trojan, and establish command-and-control access. It recommends auditing dependency trees and lockfiles and rotating credentials on affected hosts.

### Source excerpt

A supply chain attack compromised all 143 @mastra packages. Chainguard customers stayed protected through malware blocking and source-built libraries.

## The expanding threat landscape: Chainguard now scans source code for traditional malware and "greyware"

DevFeed: [The expanding threat landscape: Chainguard now scans source code for traditional malware and "greyware"](<https://devfeed.tech/articles/the-expanding-threat-landscape-chainguard-now-scans-source-code-for-traditional-malware-and-greyware-13252.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-expanding-threat-landscape-chainguard-now-scans-source-code-for-traditional-malware-and-greyware>)

Published: 2026-06-09T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Code](<https://devfeed.tech/topics/code.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [npm](<https://devfeed.tech/topics/npm.md>), [npm packages](<https://devfeed.tech/topics/npm-packages.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [ecosystems](<https://devfeed.tech/tags/ecosystems.md>), [greyware](<https://devfeed.tech/tags/greyware.md>), [greyware-scanner](<https://devfeed.tech/tags/greyware-scanner.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [malware](<https://devfeed.tech/tags/malware.md>), [malware-prevention](<https://devfeed.tech/tags/malware-prevention.md>), [malware-scanner](<https://devfeed.tech/tags/malware-scanner.md>), [npm](<https://devfeed.tech/tags/npm.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [packages](<https://devfeed.tech/tags/packages.md>), [scanner](<https://devfeed.tech/tags/scanner.md>), [security](<https://devfeed.tech/tags/security.md>), [source](<https://devfeed.tech/tags/source.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>)

### AI overview

Chainguard has introduced a source code scanner that detects traditional malware and "greyware," harmful packages that may perform actions such as credential theft, command interception, API key harvesting, or persistent remote access. The scanner currently protects npm packages, scans more than 100,000 packages daily, and has blocked more than 52,000 packages identified as malware or greyware.

### Source excerpt

Chainguard's new scanner blocks malware and 'greyware' before it reaches developers, protecting 100,000+ packages daily across open source ecosystems.

## Miasma Phantom Gyp npm attack: 57 packages, 286 malicious versions hijack CI/CD pipelines via binding.gyp

DevFeed: [Miasma Phantom Gyp npm attack: 57 packages, 286 malicious versions hijack CI/CD pipelines via binding.gyp](<https://devfeed.tech/articles/miasma-phantom-gyp-npm-attack-57-packages-286-malicious-versions-hijack-ci-cd-pipelines-via-binding-gyp-12928.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-artifacts-safe-from-miasma-phantom-gyp-npm-attack>)

Published: 2026-06-05T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [npm packages](<https://devfeed.tech/topics/npm-packages.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Security](<https://devfeed.tech/topics/security.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [npm](<https://devfeed.tech/topics/npm.md>), [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-actions](<https://devfeed.tech/tags/chainguard-actions.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [malware](<https://devfeed.tech/tags/malware.md>), [miasma](<https://devfeed.tech/tags/miasma.md>), [npm-security](<https://devfeed.tech/tags/npm-security.md>), [packages](<https://devfeed.tech/tags/packages.md>), [phantom-gyp](<https://devfeed.tech/tags/phantom-gyp.md>), [shai-hulud](<https://devfeed.tech/tags/shai-hulud.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

This article describes the Miasma Phantom Gyp npm supply-chain attack, in which attackers published 286 malicious versions across 57 packages. The self-replicating worm targeted CI/CD pipelines, harvested credentials, poisoned additional packages, modified workflows, and planted backdoor configurations in AI coding assistant directories. It also explains that Chainguard customers were protected because Chainguard Libraries builds from source and blocked the malicious versions.

### Source excerpt

A new npm supply chain worm compromised 57 packages and 286 versions. Learn how Chainguard blocked the attack and protected customers by design.

## Chainguard customers safe from Mini Shai-Hulud worm targeting @redhat-cloud-services npm packages with 100K+ weekly downloads

DevFeed: [Chainguard customers safe from Mini Shai-Hulud worm targeting @redhat-cloud-services npm packages with 100K+ weekly downloads](<https://devfeed.tech/articles/chainguard-customers-safe-from-mini-shai-hulud-worm-targeting-redhat-cloud-services-npm-packages-with-100k-weekly-downloads-12938.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-customers-safe-from-mini-shai-hulud-worm-targeting-redhat-cloud-services-npm-packages>)

Published: 2026-06-01T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [npm](<https://devfeed.tech/topics/npm.md>), [Security](<https://devfeed.tech/topics/security.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [npm packages](<https://devfeed.tech/topics/npm-packages.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [obfuscation](<https://devfeed.tech/topics/obfuscation.md>), [payload](<https://devfeed.tech/topics/payload.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>)

Tags: [chainguard-actions](<https://devfeed.tech/tags/chainguard-actions.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [endpoint-security](<https://devfeed.tech/tags/endpoint-security.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mini-shai-hulud](<https://devfeed.tech/tags/mini-shai-hulud.md>), [npm](<https://devfeed.tech/tags/npm.md>), [obfuscation](<https://devfeed.tech/tags/obfuscation.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [packages](<https://devfeed.tech/tags/packages.md>), [payload](<https://devfeed.tech/tags/payload.md>), [red-hat](<https://devfeed.tech/tags/red-hat.md>), [redhat-cloud-services](<https://devfeed.tech/tags/redhat-cloud-services.md>), [security](<https://devfeed.tech/tags/security.md>), [shai-hulud](<https://devfeed.tech/tags/shai-hulud.md>), [tokens](<https://devfeed.tech/tags/tokens.md>)

### AI overview

The article reports that the Mini Shai-Hulud worm compromised more than 90 @redhat-cloud-services npm packages through a hijacked GitHub account and GitHub Actions OIDC trusted publishing. The worm spreads tampered packages and malicious workflows, executes an obfuscated payload during installation, and steals cloud, Vault, GitHub, npm, and CI credentials. Chainguard customers using Chainguard Libraries for JavaScript and Chainguard Actions were unaffected.

### Source excerpt

A new npm worm hit 90+ Red Hat packages. Chainguard customers stayed protected by blocking install-time scripts and hardening CI/CD workflows.

## Chainguard and Upwind: Secure what you build. Verify what you run.

DevFeed: [Chainguard and Upwind: Secure what you build. Verify what you run.](<https://devfeed.tech/articles/chainguard-and-upwind-secure-what-you-build-verify-what-you-run-12926.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-and-upwind-secure-what-you-build-verify-what-you-run>)

Published: 2026-05-26T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [malicious packages](<https://devfeed.tech/topics/malicious-packages.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-libraries-for-python](<https://devfeed.tech/tags/chainguard-libraries-for-python.md>), [chainguard-scanners](<https://devfeed.tech/tags/chainguard-scanners.md>), [chainguard-upwind](<https://devfeed.tech/tags/chainguard-upwind.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [malicious-packages](<https://devfeed.tech/tags/malicious-packages.md>), [malware-scanners](<https://devfeed.tech/tags/malware-scanners.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>), [upwind](<https://devfeed.tech/tags/upwind.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard announces that Upwind now scans Chainguard Libraries for Python. The article describes combining trusted software artifacts with runtime visibility to reduce noise and supply chain risk.

### Source excerpt

Chainguard and Upwind combine trusted, source-built artifacts with runtime verification to cut noise, reduce risk, and secure AI-era software.

## Preparing for Mythos: Practical advice for engineering teams

DevFeed: [Preparing for Mythos: Practical advice for engineering teams](<https://devfeed.tech/articles/preparing-for-mythos-practical-advice-for-engineering-teams-13203.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/preparing-for-mythos-practical-advice-for-engineering-teams>)

Published: 2026-05-26T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [ai security](<https://devfeed.tech/topics/ai-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [anthropic](<https://devfeed.tech/topics/anthropic.md>), [exploit chaining](<https://devfeed.tech/topics/exploit-chaining.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [cURL](<https://devfeed.tech/topics/curl.md>)

Tags: [advice](<https://devfeed.tech/tags/advice.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [ai-vulnerability-remediation](<https://devfeed.tech/tags/ai-vulnerability-remediation.md>), [anthropic](<https://devfeed.tech/tags/anthropic.md>), [article](<https://devfeed.tech/tags/article.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-for-ai](<https://devfeed.tech/tags/chainguard-for-ai.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [exploit-chaining](<https://devfeed.tech/tags/exploit-chaining.md>), [exploits](<https://devfeed.tech/tags/exploits.md>), [mythos](<https://devfeed.tech/tags/mythos.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [work](<https://devfeed.tech/tags/work.md>)

### AI overview

This opinion assesses the security implications of Anthropic's Mythos model and argues that defenders should use AI-assisted methods to identify and remediate vulnerabilities. It says Mythos appears especially capable at exploiting vulnerabilities and chaining exploits, while a test on curl found one new non-critical vulnerability.

### Source excerpt

Anthropic's Mythos raises the stakes for software security. Learn how to survive faster exploits with secure-by-default supply chains and AI-assisted defense.

## Mini Shai-Hulud npm Attack: AntV Ecosystem Compromise (May 2026)

DevFeed: [Mini Shai-Hulud npm Attack: AntV Ecosystem Compromise (May 2026)](<https://devfeed.tech/articles/mini-shai-hulud-npm-attack-antv-ecosystem-compromise-may-2026-13160.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/mini-shai-hulud-npm-attack-antv-ecosystem-compromise-may-2026>)

Published: 2026-05-19T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [npm packages](<https://devfeed.tech/topics/npm-packages.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Data visualization](<https://devfeed.tech/topics/data-visualization.md>), [Aeternum](<https://devfeed.tech/topics/aeternum.md>), [stripe](<https://devfeed.tech/topics/stripe.md>), [Raycast extension](<https://devfeed.tech/topics/raycast-extension.md>), [React UI animations](<https://devfeed.tech/topics/react-ui-animations.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [antv](<https://devfeed.tech/tags/antv.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-npm](<https://devfeed.tech/tags/chainguard-npm.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mini-shai-hulud](<https://devfeed.tech/tags/mini-shai-hulud.md>), [npm](<https://devfeed.tech/tags/npm.md>), [npm-malware](<https://devfeed.tech/tags/npm-malware.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [react](<https://devfeed.tech/tags/react.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

The article reports that a compromised npm maintainer account pushed malicious versions of 314 packages in Alibaba's AntV ecosystem on May 19, 2026. It describes the Mini Shai-Hulud campaign, which uses install hooks and obfuscated Bun scripts to deliver malware and harvest developer credentials.

### Source excerpt

The Mini Shai-Hulud npm worm compromised 314 packages in the AntV ecosystem on May 19, 2026 -- including echarts-for-react and timeago.js.

## Building for the AI era: Chainguard partners with Endor Labs

DevFeed: [Building for the AI era: Chainguard partners with Endor Labs](<https://devfeed.tech/articles/building-for-the-ai-era-chainguard-partners-with-endor-labs-12905.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/building-for-the-ai-era-chainguard-partners-with-endor-labs>)

Published: 2026-05-19T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Library](<https://devfeed.tech/topics/library.md>), [Agent Skill](<https://devfeed.tech/topics/agent-skill.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-coding-agents](<https://devfeed.tech/tags/ai-coding-agents.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cves](<https://devfeed.tech/tags/cves.md>), [endor](<https://devfeed.tech/tags/endor.md>), [endor-labs](<https://devfeed.tech/tags/endor-labs.md>), [observability](<https://devfeed.tech/tags/observability.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard partners with Endor Labs to help teams building with AI coding agents secure the software supply chain. Chainguard provides source-built artifacts, daily rebuilds, signed SBOMs, and SLSA Level 3 provenance, while Endor Labs analyzes application context to identify vulnerabilities that are genuinely reachable and exploitable.

### Source excerpt

Chainguard and Endor Labs help teams build securely at AI speed with source-built artifacts, exploitability analysis, and fewer vulnerabilities to triage.

## Node-ipc compromised: Credential stealer targets package with 500k+ weekly downloads

DevFeed: [Node-ipc compromised: Credential stealer targets package with 500k+ weekly downloads](<https://devfeed.tech/articles/node-ipc-compromised-credential-stealer-targets-package-with-500k-weekly-downloads-13188.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/node-ipc-compromised-credential-stealer-targets-package-with-500k-weekly-downloads>)

Published: 2026-05-14T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Node.js](<https://devfeed.tech/topics/node-js.md>), [Security](<https://devfeed.tech/topics/security.md>), [npm](<https://devfeed.tech/topics/npm.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>), [CommonJS](<https://devfeed.tech/topics/commonjs.md>), [Claude](<https://devfeed.tech/topics/claude.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [api-keys](<https://devfeed.tech/tags/api-keys.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [claude](<https://devfeed.tech/tags/claude.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [commonjs](<https://devfeed.tech/tags/commonjs.md>), [dns](<https://devfeed.tech/tags/dns.md>), [github](<https://devfeed.tech/tags/github.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [malware](<https://devfeed.tech/tags/malware.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [node](<https://devfeed.tech/tags/node.md>), [node-ipc](<https://devfeed.tech/tags/node-ipc.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [node-malware](<https://devfeed.tech/tags/node-malware.md>), [node-worm](<https://devfeed.tech/tags/node-worm.md>), [npm](<https://devfeed.tech/tags/npm.md>), [npm-malware](<https://devfeed.tech/tags/npm-malware.md>), [payload](<https://devfeed.tech/tags/payload.md>), [security](<https://devfeed.tech/tags/security.md>), [sha-256](<https://devfeed.tech/tags/sha-256.md>), [shai-hulud](<https://devfeed.tech/tags/shai-hulud.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [terraform](<https://devfeed.tech/tags/terraform.md>)

### AI overview

Three malicious versions of the node-ipc npm package harvested and exfiltrated credentials from cloud providers, SSH, Kubernetes, CI/CD, version-control tools, and AI APIs. The article reports that Chainguard customers were not affected.

### Source excerpt

Malicious node-ipc packages stole cloud, SSH, Kubernetes, and AI keys. Chainguard customers stayed protected through source-built libraries.

[Next page](<https://devfeed.tech/tags/chainguard-libraries.md?cursor=WyIyMDI2LTA1LTE0VDAwOjAwOjAwKzAwOjAwIiwgIjg1MDA3ZmQwLTliYjEtNDIwYi05OGYzLWNhZmIyNWQxNmMxNiJd>)