Blog

Supply chain security, written from the inside.

Attack post-mortems, technical deep-dives, and practical guidance for engineering teams running on-premises dependency security.

Trust Then Verify or Verify Then Trust? Choosing How ShieldedStack Handles the Unknown

Security policies are easy when the answer is already known. A package is explicitly approved, explicitly denied, or has a known vulnerability above the organization's accepted threshold. The harder question is what to do when a developer requests a package version that does not yet have sufficiently current assessment information. ShieldedStack gives each workspace two ways to answer that question: Trust Then Verify and Verify Then Trust. Both use the same policy controls. They differ in how

Read more

19 August 2026

5 min read

A simple architecture for securing every package

Modern software supply chains are complicated enough, CI, local developer machines, multiple environments. The system protecting them should not add more complexity than necessary. ShieldedStack's long-running application architecture is built around three clear units: the Portal, the Proxy, and the Worker. Each has one distinct purpose and is deployed separately, so capacity can be added where it is needed. That gives customers a deployment that is easy to understand on day one and straightfo

Read more

17 August 2026

4 min read

The Weekly Dependency Threat Report: 2026-08-15

This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries. 1. spoint (npm) * Package: https://www.npmjs.com/package/spoint * Severity: medium * Affected versions: 0.1.695-0.1.700 * Downloads: 20346 * First seen: 11 August 2026 at 01:14 UTC This appears to be a very VERY sneaky account compromise that introduces an infostealer. Versions 0.1.695 to 0.1.700 add two additional dependencies: node-fetch and dotenv. These two new

Read more

17 August 2026

5 min read

The Weekly Dependency Threat Report: 2026-08-08

This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries. 1. @servicetitan/install (npm) * Package: https://www.npmjs.com/package/@servicetitan/install * Severity: high * Affected versions: 38.1.1, 38.1.2, 38.1.3, 38.1.4, 38.1.5 * Downloads: 27414 * First seen: 4 August 2026 at 13:43 UTC Compromised npm package infected via worm propagation in the Shai-Hulud/ChainDrop supply chain attack (Aug 4, 2026). Malicious versions c

Read more

10 August 2026

5 min read

The Weekly Dependency Threat Report: 2026-08-01

This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries. 1. @andrewstory18/is-real-odd (npm) * Package: https://www.npmjs.com/package/@andrewstory18/is-real-odd * Severity: high * Affected versions: all * Downloads: 2460805 * First seen: 1 August 2026 at 09:55 UTC Typosquat of the well-known is-odd package (copied name, description, README, and false author credit to Jon Schlinkert). The legitimate-looking index.js is a d

Read more

4 August 2026

7 min read

The Weekly Dependency Threat Report: 2026-07-25

This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries. 1. yuinpm (npm) * Package: https://www.npmjs.com/package/yuinpm * Severity: high * Affected versions: 0.0.1-security * Downloads: 7767 * First seen: 23 July 2026 at 23:21 UTC Malicious package detected. 2. @apexfdn/apex (npm) * Package: https://www.npmjs.com/package/@apexfdn/apex * Severity: low * Affected versions: 1.0.28 * Downloads: 1821 * First seen: 22

Read more

27 July 2026

2 min read

The Weekly Dependency Threat Report: 2026-07-19

This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries. 1. crypto-hasher (npm) * Package: https://www.npmjs.com/package/crypto-hasher * Severity: high * Affected versions: 0.0.1-security * Downloads: 1731879 * First seen: 15 July 2026 at 10:47 UTC Malicious package detected. 2. @oliviamcdaniel12/safer-buffer (npm) * Package: https://www.npmjs.com/package/@oliviamcdaniel12/safer-buffer * Severity: critical * Affecte

Read more

19 July 2026

3 min read

The Weekly Dependency Threat Report: 2026-07-11

This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries. 1. @andrewstory18/is-real-odd (npm) * Package: https://www.npmjs.com/package/@andrewstory18/is-real-odd * Severity: high * Affected versions: all * Downloads: 1463379 * First seen: 10 July 2026 at 08:52 UTC Malicious package detected. Behaviors: install-time execution. 2. @injectivelabs/sdk-ts (npm) * Package: https://www.npmjs.com/package/@injectivelabs/sdk-ts

Read more

13 July 2026

4 min read

The Weekly Dependency Threat Report: 2026-07-05

This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries. 1. zhuanhua (npm) * Package: https://www.npmjs.com/package/zhuanhua * Severity: medium * Affected versions: all * Downloads: 9165 * First seen: 1 July 2026 at 22:55 UTC Hijacks browser pages that load zhuanhua@1.1.107 by injecting a full-screen iframe pointed at https://tckyv.ygh8tas.icu during browser execution. The payload is triggered by DOMContentLoaded or the i

Read more

5 July 2026

3 min read

The Weekly Dependency Threat Report: 2026-06-27

This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries. 1. @immobiliarelabs/backstage-plugin-gitlab-backend (npm) * Package: https://www.npmjs.com/package/@immobiliarelabs/backstage-plugin-gitlab-backend * Severity: critical * Affected versions: 3.0.3, 4.0.2, 5.2.1, 6.13.1, 7.0.2 * Downloads: 12844 * First seen: 26 June 2026 at 16:06 UTC Multiple versions of @immobiliarelabs/backstage-plugin-gitlab-backend were trojanize

Read more

29 June 2026

6 min read

The Weekly Dependency Threat Report: 2026-06-20

This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries. 1. @mastra/client-js (npm) * Package: https://www.npmjs.com/package/@mastra/client-js * Severity: critical * Affected versions: 1.24.1 * Downloads: 250837 * First seen: 17 June 2026 at 03:32 UTC @mastra/client-js@1.24.1 was trojanized as part of a coordinated supply chain attack on the @mastra npm organization on 2026-06-17 between 01:12-02:24 UTC. A compromised mai

Read more

22 June 2026

8 min read

The hidden risk of license changes in open-source dependencies

Most teams think about dependency risk in terms of CVEs, malware, and typosquatting. But there is another kind of supply-chain risk that can hit just as hard: a package you already trust can change its license in a later release, turning a routine upgrade into a legal and operational problem. That is why license-change alerts matter. When a dependency moves from a permissive license to AGPL, a commercial license, or some other policy-breaking model, the right time to catch it is before the pack

Read more

15 June 2026

4 min read

The Weekly Dependency Threat Report: 2026-06-14

This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries. 1. @builder.io/dev-tools (npm) * Package: https://www.npmjs.com/package/@builder.io/dev-tools * Severity: critical * Affected versions: 1.65.0 * Downloads: 35136 * First seen: 11 June 2026 at 00:19 UTC Malicious package detected. Behaviors: data exfiltration, code execution, obfuscated code. 2. events-runtime (npm) * Package: https://www.npmjs.com/package/events

Read more

15 June 2026

3 min read

The Weekly Dependency Threat Report: 2026-06-07

This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries. 1. puppeteer-core (npm) * Package: https://www.npmjs.com/package/puppeteer-core * Severity: critical * Affected versions: 25.1.0 * Downloads: 18014723 * First seen: 2 June 2026 at 13:38 UTC Typosquatting attack. Similar to popular package: unknown. Behaviors: data exfiltration, code execution, obfuscated code. 2. @puppeteer/browsers (npm) * Package: https://www.

Read more

8 June 2026

5 min read

The Weekly Dependency Threat Report: 2026-05-31

This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries. 1. events-channel (npm) * Package: https://www.npmjs.com/package/events-channel * Severity: critical * Affected versions: all * Downloads: 39778 * First seen: 25 May 2026 at 16:42 UTC Sophisticated npm typosquatting supply chain attack combining fake 15-year git history forgery with cryptocurrency theft malware. Attacker created throwaway account 'tamekacooke21' on

Read more

1 June 2026

3 min read

NuGet Supply Chain Security: A Practical Guide

Your NuGet packages are a bigger attack surface than your code. Think about it: when was the last time you audited a dependency before running dotnet add package? You check the download count, maybe the GitHub stars, and move on. Meanwhile, you're trusting not just that package author, but every transitive dependency, every maintainer with commit access, and every build system that touched the release. The 2021 SolarWinds breach wasn't a sophisticated zero-day exploit. It was a compromised bui

Read more

29 May 2026

4 min read

The Weekly Dependency Threat Report: 2026-05-25

This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries. 1. durabletask (pypi) * Package: https://pypi.org/project/durabletask/ * Severity: critical * Affected versions: 1.4.1-1.4.3 * Downloads: 386297 * First seen: 19 May 2026 at 17:58 UTC TeamPCP compromised a legitimate PyPI contributor and published three malicious versions of durabletask (1.4.1, 1.4.2, 1.4.3) to PyPI — a Python package implementing Microsoft Azure's

Read more

25 May 2026

5 min read

GitHub Actions Security Checklist for the Supply Chain Attack Era

GitHub Actions is one of the most convenient ways to automate builds, tests, releases, and deployments. It is also one of the easiest places to accidentally hand attackers a path into your software supply chain when workflow trust boundaries are too loose. That matters more now because recent supply chain incidents have followed the same pattern again and again: compromise the build path, steal a token, poison a release, and let downstream users do the rest. This checklist focuses on the mista

Read more

16 May 2026

5 min read

How ShieldedStack Uses Kiota to Keep Frontend and Backend in Sync

In ShieldedStack, the Control Plane frontend doesn’t manually define API calls. Instead, it consumes a fully generated, strongly typed TypeScript client. Built directly from the backend’s OpenAPI specification using Kiota. This approach keeps the frontend and backend in lockstep, eliminates drift, and removes a whole class of runtime errors caused by mismatched contracts. Build-Time: Generating the Client The process starts in the backend project (API). During the build, the API emits an Ope

Read more

24 April 2026

1 min read

Subscribe via RSS

New posts on supply chain attacks, dependency security, and EU sovereignty as they ship.

RSS feed