Blog

Supply chain security, written from the inside.

Attack post-mortems, technical deep-dives, and practical guidance for engineering teams running on-premises dependency security.

Ideas & analysis

Latest posts

7 articles

5 Hidden Risks in Your package.json File

A package.json file is easy to skim. You see the packages your team added, maybe a few scripts, and a version number beside each dependency. It feels like a reasonable picture of what your application installs. It is only the starting point. The versions npm actually installs are recorded in the lockfile. Those packages can bring in more packages of their own. Some can run code during installation. And a clean vulnerability report cannot tell you whether a package published this morning is saf

Read more

29 September 2026

4 min read

Trust Then Verify or Verify Then Trust? Choosing How ShieldedStack Handles the Unknown

Security policies are easy when the answer is already known. A package is explicitly approved, explicitly denied, or has a known vulnerability above the organization's accepted threshold. The harder question is what to do when a developer requests a package version that does not yet have sufficiently current assessment information. ShieldedStack gives each workspace two ways to answer that question: Trust Then Verify and Verify Then Trust. Both use the same policy controls. They differ in how

Read more

19 August 2026

5 min read

A simple architecture for securing every package

Modern software supply chains are complicated enough, CI, local developer machines, multiple environments. The system protecting them should not add more complexity than necessary. ShieldedStack's long-running application architecture is built around three clear units: the Portal, the Proxy, and the Worker. Each has one distinct purpose and is deployed separately, so capacity can be added where it is needed. That gives customers a deployment that is easy to understand on day one and straightfo

Read more

17 August 2026

4 min read

The hidden risk of license changes in open-source dependencies

Most teams think about dependency risk in terms of CVEs, malware, and typosquatting. But there is another kind of supply-chain risk that can hit just as hard: a package you already trust can change its license in a later release, turning a routine upgrade into a legal and operational problem. That is why license-change alerts matter. When a dependency moves from a permissive license to AGPL, a commercial license, or some other policy-breaking model, the right time to catch it is before the pack

Read more

15 June 2026

4 min read

NuGet Supply Chain Security: A Practical Guide

Your NuGet packages are a bigger attack surface than your code. Think about it: when was the last time you audited a dependency before running dotnet add package? You check the download count, maybe the GitHub stars, and move on. Meanwhile, you're trusting not just that package author, but every transitive dependency, every maintainer with commit access, and every build system that touched the release. The 2021 SolarWinds breach wasn't a sophisticated zero-day exploit. It was a compromised bui

Read more

29 May 2026

4 min read

A separate series

Weekly threat reports

Dependency risks and security updates, week by week.

The Weekly Dependency Threat Report: 2026-10-03

This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries. 1. whalibmob (npm) * Package: https://www.npmjs.com/package/whalibmob * Severity: critical * Affected versions: 5.33.5 * Downloads: 4681 * First seen: 30 September 2026 at 10:41 UTC This package is part of a large family (100+ identified as of September 2026) of near-identical forks of the Baileys WhatsApp Web library that inject a covert channel-subscription action

Read more

5 October 2026

5 min read

The Weekly Dependency Threat Report: 2026-09-26

This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries. 1. rrs (pypi) * Package: https://pypi.org/project/rrs/ * Severity: high * Affected versions: all * Downloads: 2282 * First seen: 21 September 2026 at 04:23 UTC The rrs package advertises itself as a multi-monitor screen capture CLI but, on invocation, captures every attached monitor and POSTs the resulting PNG/JPEG images to a hardcoded Discord webhook controlled by

Read more

28 September 2026

4 min read

The Weekly Dependency Threat Report: 2026-09-19

This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries. 1. noblox-asset.js (npm) * Package: https://www.npmjs.com/package/noblox-asset.js * Severity: critical * Affected versions: all * Downloads: 279382 * First seen: 14 September 2026 at 18:01 UTC noblox-asset.js impersonates the noblox.js Roblox API wrapper: package.json copies the legitimate package's description, homepage (github.com/noblox/noblox.js), and repository

Read more

20 September 2026

5 min read

The Weekly Dependency Threat Report: 2026-09-12

This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries. 1. tailwindcss-contact-forms (npm) * Package: https://www.npmjs.com/package/tailwindcss-contact-forms * Severity: critical * Affected versions: 0.5.6 * Downloads: 1417 * First seen: 10 September 2026 at 12:55 UTC NullReceiver The file contains heavily obfuscated code that executes shell commands via 'spawn' with '-e' and communicates with Ethereum RPC endpoints. It

Read more

15 September 2026

4 min read

The Weekly Dependency Threat Report: 2026-09-05

This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries. 1. @crysnovax/baileys (npm) * Package: https://www.npmjs.com/package/@crysnovax/baileys * Severity: critical * Affected versions: 2.8.3 * Downloads: 4127 * First seen: 4 September 2026 at 06:26 UTC @crysnovax/baileys is a renamed fork of the Baileys WhatsApp Web library. On every successful connection (connection.update with connection === 'open', wired in lib/Socke

Read more

7 September 2026

10 min read

Subscribe via RSS

New posts on supply chain attacks, dependency security, and EU sovereignty as they ship.

RSS feed