







Against dependency cooldowns as a response to supply chain attacks
Package Managers Need to Cool Down
A survey of dependency cooldown support across package managers and update tools.

The Axios supply chain attack used individually targeted social engineering
The Axios team have published a full postmortem on the supply chain attack which resulted in a malware dependency going out in a release the other day, and it involved …
The Axios supply chain attack used individually targeted social engineering
The Axios team have published a full postmortem on the supply chain attack which resulted in a malware dependency going out in a release the other day, and it involved …
Dependency Cultures - Richard Feldman | SSW 2026
Socket - Block zero-day supply chain attacks
Socket fights vulnerabilities and provides visibility, defense-in-depth, and proactive supply chain protection for JavaScript, Python, and Go dependen...

The secure way to release an npm package in 2026—Martian Chronicles, Evil Martians’ team blog
How to protect your npm package from being stolen in a supply chain attack and improve its position in security ratings

keyv and cacheable npm Package Hijacked in Supply Chain Attack | Wiz Blog
Wiz Research is actively investigating an ongoing software supply chain attack affecting multiple keyv/cacheable npm packages.


Download pumping: New npm deception technique for supply chain attacks
Learn how attackers exploit automated bot traffic as part of software supply chain attacks to artificially inflate download counters and mask malicious payloads as legitimate.

Supply chain attack on arrayref | Rust Blog
Empowering everyone to build reliable and efficient software.

Post Mortem: axios npm supply chain compromise · Issue #10636 · axios/axios
Post Mortem: axios npm supply chain compromise Date: March 31, 2026 Author: Jason Saayman Status: Remediation in progress On March 31, 2026, two malicious versions of axios (1.14.1 and 0.30.4) were...
Pentagon moves to designate Anthropic as a supply-chain risk | TechCrunch
"We don't need it, we don't want it, and will not do business with them again," the president wrote in the post.

Pentagon says it is labeling AI company Anthropic a supply chain risk 'effective immediately'
The Trump administration is following through with its threat to designate artificial intelligence company Anthropic as a supply chain risk in an unprecedented move that could force other government contractors to stop using the AI chatbot Claude.
Mercor Breach Linked to LiteLLM Supply-Chain Attack
A LiteLLM supply-chain compromise enabled attackers to harvest credentials and access internal environments at scale at Mercor. The firm was the first to confirm a
Security Update: Suspected Supply Chain Incident | liteLLM
As of 2:00 PM ET on March 24, 2026

One of the more nagging questions atm relates to path-dependency: Given #atproto / Bluesky largely emerged from (the ruins of) the other place, are we falling for Russell Ackoff's "trying to do the wrong thing righter" trap? 🤔