# software supply-chain attack

Published articles for software supply-chain attack.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain

DevFeed: [Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain](<https://devfeed.tech/articles/connecting-the-dots-securing-the-overlooked-corners-of-the-software-development-lifecycle-sdlc-supply-chain-7758.md>)

Original publisher: [Read original article](<https://unit42.paloaltonetworks.com/sdlc-supply-chain/>)

Author: Yaron Avital

Published: 2026-08-21T23:00:21Z

Content type: article

Language: en

Sources: [Unit 42](<https://devfeed.tech/sources/unit-42.md>)

Topics: [sdlc](<https://devfeed.tech/topics/sdlc.md>), [Security](<https://devfeed.tech/topics/security.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [npm](<https://devfeed.tech/topics/npm.md>), [Bun](<https://devfeed.tech/topics/bun.md>), [Python](<https://devfeed.tech/topics/python.md>), [Claude Code](<https://devfeed.tech/topics/claude-code.md>), [vs-code](<https://devfeed.tech/topics/vs-code.md>), [Claude](<https://devfeed.tech/topics/claude.md>), [Ethereum](<https://devfeed.tech/topics/ethereum.md>)

Tags: [blockchain](<https://devfeed.tech/tags/blockchain.md>), [c2](<https://devfeed.tech/tags/c2.md>), [chaindrop](<https://devfeed.tech/tags/chaindrop.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [claude-code](<https://devfeed.tech/tags/claude-code.md>), [general](<https://devfeed.tech/tags/general.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [insights](<https://devfeed.tech/tags/insights.md>), [malware](<https://devfeed.tech/tags/malware.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [persistence](<https://devfeed.tech/tags/persistence.md>), [python](<https://devfeed.tech/tags/python.md>), [sdlc](<https://devfeed.tech/tags/sdlc.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-attack](<https://devfeed.tech/tags/software-supply-chain-attack.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vs-code](<https://devfeed.tech/tags/vs-code.md>)

### AI overview

Unit 42 describes how software supply-chain attackers are targeting developer tools, CI/CD pipelines, accounts, packages, setup scripts and developer environments before software reaches production. It examines the ChainDrop npm worm, which used malicious preinstall hooks, a Bun runtime, an obfuscated payload, Python-based memory theft, stolen tokens and secrets, self-propagation, persistence in VS Code and Claude Code, and Ethereum-managed command-and-control infrastructure.

### Source excerpt

Attackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security controls The post Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain appeared first on Unit 42.

## Chainguard Libraries now available on AWS Security Hub Extended

DevFeed: [Chainguard Libraries now available on AWS Security Hub Extended](<https://devfeed.tech/articles/chainguard-libraries-now-available-on-aws-security-hub-extended-12969.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-libraries-now-available-on-aws-security-hub-extended>)

Published: 2026-08-04T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [AWS Security Hub](<https://devfeed.tech/topics/aws-security-hub.md>), [Security](<https://devfeed.tech/topics/security.md>), [software supply-chain attack](<https://devfeed.tech/topics/software-supply-chain-attack.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>)

Tags: [ai-coding](<https://devfeed.tech/tags/ai-coding.md>), [aws-security-hub](<https://devfeed.tech/tags/aws-security-hub.md>), [axios](<https://devfeed.tech/tags/axios.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [java](<https://devfeed.tech/tags/java.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [litellm](<https://devfeed.tech/tags/litellm.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mini-shai-hulud](<https://devfeed.tech/tags/mini-shai-hulud.md>), [npm](<https://devfeed.tech/tags/npm.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [python](<https://devfeed.tech/tags/python.md>), [redhat](<https://devfeed.tech/tags/redhat.md>), [redhat-cloud-services](<https://devfeed.tech/tags/redhat-cloud-services.md>), [security](<https://devfeed.tech/tags/security.md>), [shai-hulud](<https://devfeed.tech/tags/shai-hulud.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-attack](<https://devfeed.tech/tags/software-supply-chain-attack.md>), [telnyx](<https://devfeed.tech/tags/telnyx.md>)

### AI overview

Chainguard Libraries is now available through AWS Security Hub Extended's Supply Chain category. The article presents it as a malware-free catalog of Python, Java, and JavaScript dependencies intended to reduce reliance on public registries and help protect AWS workloads from software supply-chain attacks.

### Source excerpt

Chainguard Libraries is now available in AWS Security Hub Extended, delivering malware-resistant open source dependencies for AWS workloads.

## The Mastra AI Ecosystem Was Poisoned At The Registry Level

DevFeed: [The Mastra AI Ecosystem Was Poisoned At The Registry Level](<https://devfeed.tech/articles/the-mastra-ai-ecosystem-was-poisoned-at-the-registry-level-13458.md>)

Original publisher: [Read original article](<https://www.harness.io/blog/poisoning-the-pipeline-how-the-mastra-ai-ecosystem-was-poisoned-at-the-registry-level>)

Author: Roshan Piyush

Published: 2026-07-14T00:00:00Z

Content type: article

Language: en

Sources: [Harness Blog](<https://devfeed.tech/sources/harness-blog.md>)

Topics: [software supply-chain attack](<https://devfeed.tech/topics/software-supply-chain-attack.md>), [npm packages](<https://devfeed.tech/topics/npm-packages.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [TypeScript](<https://devfeed.tech/topics/typescript.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [malicious-packages](<https://devfeed.tech/tags/malicious-packages.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mastra](<https://devfeed.tech/tags/mastra.md>), [npm](<https://devfeed.tech/tags/npm.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-attack](<https://devfeed.tech/tags/software-supply-chain-attack.md>), [typescript](<https://devfeed.tech/tags/typescript.md>)

### AI overview

The article examines a June 17, 2026 software supply-chain attack targeting the Mastra AI TypeScript ecosystem. It reports that a compromised contributor account was used to publish 144 malicious packages under the official @mastra npm scope, with registry-level changes introducing the easy-day-js transitive dependency. Installations during the compromise window could expose developer workstations, CI/CD runners, and cloud environments to an information stealer.

### Source excerpt

Learn how the Mastra AI supply chain attack poisoned npm packages, impacted AI pipelines, and how Harness SCS helps detect, block, and remediate compromised dep | Blog

## Our response to the TanStack npm supply chain attack

DevFeed: [Our response to the TanStack npm supply chain attack](<https://devfeed.tech/articles/our-response-to-the-tanstack-npm-supply-chain-attack-6596.md>)

Original publisher: [Read original article](<https://openai.com/index/our-response-to-the-tanstack-npm-supply-chain-attack>)

Published: 2026-05-13T00:00:00Z

Content type: article

Language: en

Sources: [OpenAI News](<https://devfeed.tech/sources/openai-news.md>)

Topics: [OpenAI](<https://devfeed.tech/topics/openai.md>), [npm](<https://devfeed.tech/topics/npm.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [software supply-chain attack](<https://devfeed.tech/topics/software-supply-chain-attack.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>), [Security](<https://devfeed.tech/topics/security.md>), [Digital forensics](<https://devfeed.tech/topics/digital-forensics.md>), [macOS](<https://devfeed.tech/topics/macos.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [App](<https://devfeed.tech/topics/app.md>)

Tags: [app](<https://devfeed.tech/tags/app.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [macos](<https://devfeed.tech/tags/macos.md>), [malware](<https://devfeed.tech/tags/malware.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openai](<https://devfeed.tech/tags/openai.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-attack](<https://devfeed.tech/tags/software-supply-chain-attack.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

OpenAI describes its response to the TanStack npm supply-chain attack known as Mini Shai-Hulud. The article outlines the investigation, containment measures, certificate protections for macOS applications, and required application updates.

### Source excerpt

OpenAI details its response to the TanStack "Mini Shai-Hulud" supply chain attack, outlines protections taken to secure systems and signing certificates, and explains why macOS users must update OpenAI apps by June 12, 2026. Learn what happened, what was affected, and how OpenAI is strengthening defenses against evolving software supply chain threats.

## Our response to the Axios developer tool compromise

DevFeed: [Our response to the Axios developer tool compromise](<https://devfeed.tech/articles/our-response-to-the-axios-developer-tool-compromise-6305.md>)

Original publisher: [Read original article](<https://openai.com/index/axios-developer-tool-compromise>)

Published: 2026-04-10T00:00:00Z

Content type: news

Language: en

Sources: [OpenAI News](<https://devfeed.tech/sources/openai-news.md>)

Topics: [OpenAI](<https://devfeed.tech/topics/openai.md>), [software supply-chain attack](<https://devfeed.tech/topics/software-supply-chain-attack.md>), [macOS](<https://devfeed.tech/topics/macos.md>), [Security](<https://devfeed.tech/topics/security.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [ChatGPT](<https://devfeed.tech/topics/chatgpt.md>), [codex](<https://devfeed.tech/topics/codex.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>)

Tags: [apps](<https://devfeed.tech/tags/apps.md>), [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [cli](<https://devfeed.tech/tags/cli.md>), [codex](<https://devfeed.tech/tags/codex.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [macos](<https://devfeed.tech/tags/macos.md>), [openai](<https://devfeed.tech/tags/openai.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-attack](<https://devfeed.tech/tags/software-supply-chain-attack.md>)

### AI overview

OpenAI describes its response to the compromise of the Axios developer library in a broader software supply-chain attack. The company found no evidence of user-data access, system or intellectual-property compromise, or altered software, but is revoking and rotating the macOS application-signing certificate as a precaution. Users must update ChatGPT Desktop, Codex App, Codex CLI, and Atlas by May 8, 2026.

### Source excerpt

OpenAI responds to the Axios supply chain attack by rotating macOS code signing certificates, updating apps, and confirming no user data was compromised.

## Detecting Maven-Hijack-style risks in Gradle builds with the Dependency Analysis Gradle Plugin

DevFeed: [Detecting Maven-Hijack-style risks in Gradle builds with the Dependency Analysis Gradle Plugin](<https://devfeed.tech/articles/detecting-maven-hijack-style-risks-in-gradle-builds-with-the-dependency-analysis-gradle-plugin-24611.md>)

Original publisher: [Read original article](<https://blog.gradle.org/detect-maven-hijack-risks-in-gradle-with-plugin>)

Author: Laura Kassovic

Published: 2025-12-08T05:00:00Z

Content type: tutorial

Language: en

Sources: [The Gradle Blog](<https://devfeed.tech/sources/the-gradle-blog.md>)

Topics: [Gradle](<https://devfeed.tech/topics/gradle.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [software supply-chain attack](<https://devfeed.tech/topics/software-supply-chain-attack.md>), [Java](<https://devfeed.tech/topics/java.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [dependency](<https://devfeed.tech/tags/dependency.md>), [gradle](<https://devfeed.tech/tags/gradle.md>), [gradle-plugin](<https://devfeed.tech/tags/gradle-plugin.md>), [java](<https://devfeed.tech/tags/java.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-attack](<https://devfeed.tech/tags/software-supply-chain-attack.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This tutorial explains how Maven-Hijack-style attacks exploit duplicate fully qualified class names, deterministic Maven packaging order, and JVM classloader behavior in Java builds. It presents DAGP 3.5.0, the Dependency Analysis Gradle Plugin, as a defense that warns about duplicate classes and checks binary compatibility to identify potentially ambiguous bytecode.

### Source excerpt

JVM builds have lived with "duplicate classes on the classpath" for years. Most of the time, it's an annoying source of NoSuchMethodError or a "why did production suddenly break when I reordered dependencies?" kind of bug. A recent academic paper, Maven-Hijack: Software Supply Chain Attack Exploiting Packaging Order, shows that this isn't just a reliability problem, it's also a supply-chain security problem. DAGP 3.5.0 (Dependency Analysis Gradle Plugin), a popular community plugin, now provides another line of defense: in addition to warning you about duplicate classes, it checks binary compatibility when it finds them. That means it can spot cases where "the same class name" actually refers to different bytecode, which is exactly the kind of ambiguity Maven-Hijack exploits. We'll explore how to use DAGP to protect against Maven-Hijack style attacks in Gradle builds. If you've heard about supply chain vulnerabilities in the npm / Nx ecosystem, we've also written about how Continuous GRC can help block compromised packages across your org. What Maven-Hijack actually does The Maven-Hijack paper describes a class of attacks that rely on two facts about the Java ecosystem: Maven packaging order is deterministic - When building an uber-JAR, Maven walks the dependency tree in depth-first order and packages classes in that order. Dependencies earlier in that traversal "win" when there are duplicates. The JVM classloader loads the first matching class on the classpath - At runtime, the Java classloader linearly scans the classpath and loads the first class whose fully-qualified name matches the one being requested. That's enough to build an attack: The attacker finds a gadget dependency, a library that contains a class they'd love to hijack (e.g., a JDBC driver or some other central integration point). They then compromise or control an infection dependency that appears earlier in the dependency tree and publish a new version that contains a class with the same fully quali

## Enabling Secure Software Development in 2025

DevFeed: [Enabling Secure Software Development in 2025](<https://devfeed.tech/articles/enabling-secure-software-development-in-2025-13027.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/enabling-secure-software-development-in-2025>)

Published: 2025-01-14T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [DevOps](<https://devfeed.tech/topics/devops.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-customers](<https://devfeed.tech/tags/chainguard-customers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [fips](<https://devfeed.tech/tags/fips.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [software-development](<https://devfeed.tech/tags/software-development.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-attack](<https://devfeed.tech/tags/software-supply-chain-attack.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

Chainguard describes its 2025 focus on scaling secure software development through a catalog of more than 1,000 container images, source-built components, daily rebuilding, automation, vulnerability remediation, and hardened images. The company reports patching more than 55,000 CVEs and saving customers over 200,000 engineering hours in 2024.

### Source excerpt

Chainguard is building on the success they generated for their customers in 2024. Take a look back at the numbers, and see what's next for us and our users!

## Cybersecurity Venture's 2023 Software Supply Chain Attack Report

DevFeed: [Cybersecurity Venture's 2023 Software Supply Chain Attack Report](<https://devfeed.tech/articles/cybersecurity-venture-s-2023-software-supply-chain-attack-report-7881.md>)

Original publisher: [Read original article](<https://snyk.io/blog/cybersecurity-ventures-2023-software-supply-chain-attack-report/>)

Author: Sydney Milligan

Published: 2023-10-10T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [software supply-chain attack](<https://devfeed.tech/topics/software-supply-chain-attack.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Critical Infrastructure](<https://devfeed.tech/topics/critical-infrastructure.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [blog](<https://devfeed.tech/tags/blog.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [data-breaches](<https://devfeed.tech/tags/data-breaches.md>), [developer](<https://devfeed.tech/tags/developer.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [megawatt](<https://devfeed.tech/tags/megawatt.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [report](<https://devfeed.tech/tags/report.md>), [saas](<https://devfeed.tech/tags/saas.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [security-attacks](<https://devfeed.tech/tags/security-attacks.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-attack](<https://devfeed.tech/tags/software-supply-chain-attack.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article summarizes findings from Cybersecurity Ventures' 2023 Software Supply Chain Attack Report. It predicts that the global cost of software supply chain attacks could reach nearly $138 billion by 2031 and explains how software complexity, cloud applications, and operational pipelines increase supply chain risk. It describes common attack methods, including social engineering, phishing, stolen credentials, CI/CD pipeline compromise, vulnerability exploitation, open-source component targeting, typosquatting, insider threats, and cloud hijacking. The article also examines the 2020 SolarWinds attack, in which a backdoor inserted into an Orion update affected approximately 18,000 customers and put critical infrastructure operations at risk.

### Source excerpt

Cybersecurity Ventures predicts the global cost of software supply chain attacks will reach nearly $138 billion by 2031. Learn more by reading the 2023 Software Supply Chain Attack Report.