Hello! The Supply Chain Security team is here
More in Supply chain
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- Chaos, shock, private keys from a not-so-private GitLab 💻
Over the past couple of months, the attacker has been distributing trojans from several npm accounts:…
- Did someone say sandbox?
Someone said sandbox? 👀 Once again we're watching threat actors conduct unethical research. Given: Security researcher…
- The attacker publishes .bash_history view without registration and SMS
Attacker publishes .bash_history watch without registration and SMS 😱 The Supply Chain Security team sent a…
- A logging library and an infostealer to boot? No thanks
A logging library and an infostealer to boot? No thanks 👋 A lot has happened recently.…
Hello! The Supply Chain Security group is here 🩷
We scan open source in real time for malicious code. We are also responsible at ESCalator for publications about interesting findings in the Python Package Index and NPM 🏃♀️
We are pleased to announce a collaboration with the folks from PT Fusion and the release of feeds on discovered threats in OSV format (announcement). They contain information not only about malicious releases, but also, for example, about removed packages, which is also one of the risk factors that must be taken into account when continuing to use such packages.
If your company has development and you are concerned about its security, we would be glad to see you among our users 🤗
#scs
@ptescalator
More in Supply chain
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- Chaos, shock, private keys from a not-so-private GitLab 💻
Over the past couple of months, the attacker has been distributing trojans from several npm accounts:…
- Did someone say sandbox?
Someone said sandbox? 👀 Once again we're watching threat actors conduct unethical research. Given: Security researcher…
- The attacker publishes .bash_history view without registration and SMS
Attacker publishes .bash_history watch without registration and SMS 😱 The Supply Chain Security team sent a…
- A logging library and an infostealer to boot? No thanks
A logging library and an infostealer to boot? No thanks 👋 A lot has happened recently.…






