» Tag
supplychain
4 postsAsyncAPI Supply Chain Attack Delivers Miasma RAT via NPM
A supply chain attack on AsyncAPI has resulted in malicious npm packages delivering Miasma RAT. This incident reveals critical vulnerabilities.
Slopsquatting: Your Coding Agent Is a Supply-Chain Attack Vector
Slopsquatting is a supply-chain attack emerging from AI coding agents. Learn how LineageLens Trellis mitigates this risk.
Disrupting Supply Chain Attacks on NPM and GitHub Actions
Recent updates on npm and GitHub Actions aim to disrupt supply chain attacks.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comDepsGuard – A Native Cross-Platform Security Tool
DepsGuard scans npm and other managers for security vulnerabilities, enhancing protection against supply chain attacks.