Latest Articles
Aug 7, 2026 | Supply Chain Security
Shai-Hulud Returns: ChainDrop Worm Hits npm, Infecting Hundreds of Packages
The self-propagating worm is back. This time it poisoned keyv, an npm caching library that ships in millions of builds, and it plants a second trigger that fires the next time a developer just opens the project.
Jul 23, 2026 | Supply Chain Security
MetaDefender Software Supply Chain™ v4.0.0: Rebuilt Interface, Smarter Risk Analysis, and Stronger Automation
Jun 2, 2026 | Supply Chain Security
Mini Shai-Hulud: TanStack, OpenAI, and the npm Supply Chain Trap
Apr 3, 2026 | Supply Chain Security
The Axios npm Attack: How a Trusted Package Became a Malware Delivery System
Apr 2, 2026 | Supply Chain Security
EU Cyber Resilience Act (CRA): A Roadmap to Software Supply Chain and SBOM Compliance
Jan 20, 2026 | Supply Chain Security
MetaDefender Software Supply Chain™ v3.1.0: Built for Modern DevSecOps
Discover Critical Infrastructure Protection at One of OPSWAT’s Global Experience Labs
Explore More
Dec 4, 2025 | Supply Chain Security
Shai-Hulud 2.0: How to Secure Your Software Supply Chain Against the Second Wave
Sep 17, 2025 | Supply Chain Security
From Dune to npm: Shai-Hulud Worm Redefines Supply Chain Risk
Sep 12, 2025 | Supply Chain Security
2 Billion npm Downloads at Risk From Crypto Malware: A Wake-Up Call for Open-Source Supply Chain Security
Jul 9, 2025 | Supply Chain Security
IngressNightmare: CVE-2025-1974 Remote Code Execution Vulnerability & Remediation
Apr 29, 2025 | Supply Chain Security
MetaDefender Software Supply Chain v2.5.0: Faster Triage, Stronger Compliance
Apr 22, 2025 | Supply Chain Security