Joyfill npm packages ran a RAT when imported
Two Joyfill prereleases contained a RAT loaded on module import. We explain the blockchain C2 resolver, exposure evidence and response plan.
Risk across dependencies, packages, suppliers and CI/CD, with practical ways to verify provenance, integrity and the organisational impact of change.
Two Joyfill prereleases contained a RAT loaded on module import. We explain the blockchain C2 resolver, exposure evidence and response plan.
Learn what an SBOM is, how CycloneDX and SPDX differ, where VEX fits, which minimum elements matter and how to build a trustworthy CI/CD process.
AI found hundreds of potential flaws across major open-source projects, but triage, reproduction, safe patches and maintainer review remain essential.
Signing without key management (Sigstore) and verifiable build provenance (SLSA) are the new supply chain defense. We translate Fulcio, Rekor, cosign and SLSA levels.
A single dependency can compromise thousands of companies at once. We explain how supply chain attacks work and how to limit dependency risk.
Your security ends at your weakest supplier. How to assess contractor risk, what to put in contracts and how to monitor suppliers efficiently.
Pickle, SafeTensors, ONNX, and AI checkpoints explained: prevent code execution and build a controlled, verifiable model supply-chain pipeline.
In May 2026 the Mini Shai-Hulud worm hit npm and PyPI at once, stealing CI/CD secrets. We analyse the attack and how to harden your pipeline.
Technical analysis of the March 2026 supply-chain wave: hijacked Trivy and KICS tags, LiteLLM .pth execution, axios, CI/CD secrets and recovery.
In autumn 2025 the Shai-Hulud worm infected hundreds of npm packages, spreading itself. We analyse the supply chain attack and how to secure your pipeline.
In 2025, stolen OAuth tokens from Salesloft exposed hundreds of firms' Salesforce data — with no cracked passwords. A lesson on integration risk.
We turn current threats into role-based training, safe exercises and a clear reporting path. The free Academy remains available for self-directed learning.