Software Supply Chain Attacks

Security/Network/Database

The Severity of React/Next.js Vulnerabilities Revealed by React2Shell – Software Supply Chain Attacks That Can No Longer Be Ignored

Since the latter half of 2025, software supply chain attacks have been surging, with the npm Shai-Hulud incident as a re...
Security/Network/Database

[Warning]The Largest npm Software Supply Chain Attack in History: Shai-Hulud ~ Over 20 Malicious OSS Packages Downloaded 2 Million Times in One Week

Recently, the npm ecosystem faced its third large-scale attack.Following the recent hijacking of the nx package and atta...
DevOps/Agile

JFrog Curation in Practice: Lessons Learned from the npm Software Supply Chain Attack

In a recent blog post titled “The Largest npm Software Supply Chain Attack in History: Shai-Hulud ~ Over 20 Malicious OS...
Copied title and URL