appsec.fyi

Supply Chain — A Practical Guide

A curated AppSec resource library covering XSS, SQLi, SSRF, IDOR, RCE, XXE, OSINT, and more.

Supply Chain: A Practical Guide

Curated and synthesized by . Last updated 2026-06-29. Synthesized from 907 of 907 curated resources. Browse all 907 Supply Chain resources →

Problem Framing

The software supply chain, once considered a relatively contained security perimeter, has evolved into a complex, interconnected web of dependencies, third-party services, and automated development pipelines. This complexity inherently introduces significant attack vectors that malicious actors are increasingly exploiting. Attacks targeting the software supply chain are not merely about compromising a single application; they aim to compromise the trust inherent in the development and distribution ecosystem itself. This can lead to widespread impact, affecting thousands of downstream users, critical infrastructure, and sensitive data. The adversarial landscape is rapidly evolving, with threat actors demonstrating sophisticated techniques to bypass traditional security controls and exploit human trust and system automation.

Supply chain attacks manifest in various forms, often leveraging the very infrastructure and processes designed for efficient software delivery. This includes poisoning package registries, hijacking developer accounts, compromising CI/CD pipelines, and exploiting vulnerabilities in the tools developers rely on daily [1][2][3]. The rise of AI-assisted development tools and autonomous agents has introduced new dimensions to these attacks, with AI being used for reconnaissance, payload generation, and even autonomous progression of attacks, while simultaneously becoming a target itself [4][5]. The scale and speed at which these attacks can propagate, often through self-replicating malware or worms, underscore the urgency and difficulty in detection and remediation [6][7].

Core Mechanics of Supply Chain Attacks

Supply chain attacks fundamentally exploit the trust relationships and automated processes within the software development lifecycle. Attackers aim to inject malicious code or compromise trusted artifacts at any point from source code creation to final deployment. Several core mechanics underpin these attacks:

Notable Techniques and Attack Patterns

The landscape of supply chain attacks is constantly evolving, with threat actors developing increasingly sophisticated methods. Several notable techniques and patterns have emerged:

Detection and Prevention

Securing the software supply chain requires a multi-layered approach that addresses vulnerabilities at every stage of the development lifecycle.

Detection Strategies

Prevention Strategies

Tooling Landscape

A diverse set of tools has emerged to address the multifaceted challenges of supply chain security. These tools operate at different stages of the development lifecycle and cover various aspects of threat detection and prevention.

Recent Developments

The supply chain security landscape is in constant flux, driven by rapid innovation in attacker tactics and defensive measures. Recent developments highlight a maturing understanding of the threat and increasingly sophisticated responses:

Where to Go Deeper

For practitioners seeking to deepen their understanding and capabilities in supply chain security, several avenues offer continuous learning and practical guidance.

Sources cited in this guide

  1. Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack — thehackernews.com
  2. Hackers Poisoned 170 Popular npm and PyPI Packages in a 5-Hour Blitz TanStack Mistral AI UiPath Hit — europe-infos.fr
  3. Mastra npm Supply Chain Attack: 140 Packages Backdoored via easy-day-js Typosquat — stepsecurity.io
  4. GitHub Actions Supply Chain Flaw Exposes Microsoft and Google to Free-Account Hijack — techtimes.com
  5. Weaponizing AI Coding Agents for Malware in the Nx Malicious Package Security Incident — snyk.io
  6. Shai-Hulud: Ongoing Package Supply Chain Worm Delivering Data-Stealing Malware — wiz.io
  7. Microsofts GitHub repositories taken offline amid Miasma supply chain attack — computing.co.uk
  8. Everybody's shipping code they can't read — aikido.dev
  9. Container Security Requires More Than Scanning: Why Provenance Verification Matters Before Deployment — cybersecurity-insiders.com
  10. npm Supply Chain Attack: North Korea Backdoored 144 AI Packages in 88 Minutes — techtimes.com
  11. Supply-chain attack injects backdoor on ShapedPlugin WordPress software — cyberinsider.com
  12. Arch Linux supply chain attack spreads to 1900 AUR packages — news.risky.biz
  13. Widespread npm Supply Chain Attack: Breaking Down Impact & Scope Across Debug, Chalk, and Beyond — wiz.io
  14. Critical Supply Chain Attack Compromises 32 Red Hat @redhat-cloud-services NPM Packages with Credential-Stealing Malware — rescana.com
  15. Multiple redhat-cloud-services npm Packages compromised — stepsecurity.io
  16. Primer on GitHub Actions Security - Threat Model, Attacks and Defenses (Part 1/2) — wiz.io
  17. The npm Threat Landscape: Attack Surface and Mitigations (Updated June 2) — unit42.paloaltonetworks.com
  18. Mini Shai-Hulud malware compromises hundreds of open-source packages in sprawling supply-chain attack — cyberscoop.com
  19. Mini Shai-Hulud attack compromises hundreds of npm PyPI packages — scworld.com
  20. How “Clinejection” Turned an AI Bot into a Supply Chain Attack — snyk.io
  21. TanStack weighs invitation-only pull requests after supply chain attack — devclass.com
  22. 5 Supply Chain Attacks in 48 Hours: Why Securing One Layer Is Not Enough — stepsecurity.io
  23. New Shai-Hulud Miasma Wave Hits Hundreds of npm Packages — sonatype.com
  24. Node-gyp Supply Chain Compromise — snyk.io
  25. Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign — microsoft.com
  26. Preventing Future Supply Chain Attacks: The OX Guide to Version Pinning Installation Cooldown and Defense in Depth — ox.security
  27. [tl;dr sec] #334 - Thinkst's Package Proxy, OpenAI Daybreak, AI Agents & Canaries — tldrsec.com
  28. Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp — snyk.io
  29. 1800 Hit in Mini Shai-Hulud Attack on SAP Lightning Intercom — securityweek.com
  30. SAP npm Supply Chain Attack Targets Developer Credentials — esecurityplanet.com
  31. How a Poisoned Security Scanner Became the Key to Backdooring LiteLLM — snyk.io
  32. Red Hat npm Packages Hit by Miasma Credential-Stealing Attack — socprime.com
  33. Multiple JetBrains IDE plugins caught stealing AI keys — aikido.dev
  34. Dismantling a Critical Supply Chain Risk in VSCode Extension Marketplaces — wiz.io
  35. How Koi Protects Against Developer Supply Chains — paloaltonetworks.com
  36. GitHub Internal Repositories Breached via Compromised Nx Console VS Code Extension: 2026 Supply Chain Cybersecurity Incident Analysis — rescana.com
  37. TrapDoor Supply Chain Attack Actively Exploiting npm PyPI and CratesIO to Steal Developer Credentials in Crypto DeFi Solana and AI Sectors — rescana.com
  38. Supply-chain attacks take aim at your AI coding agents — csoonline.com
  39. OpenAI Codex tool with over 29000 downloads linked to malicious npm supply chain attack stealing authentication tokens — techradar.com
  40. Stealer Backdoor Found in 3 Node-IPC Versions Targeting Developer Secrets — thehackernews.com
  41. Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT — snyk.io
  42. QLNX Threat Actors Steal Developer Credentials For Supply Chain Attacks — cyberpress.org
  43. Supply Chain Campaign Targets SAP npm Packages with Credential-Stealing Malware — wiz.io
  44. TeamPCPs Mini Shai-Hulud Campaign Breaches TanStack npm — cybermagazine.com
  45. How a Malicious Google Skill on ClawHub Tricks Users Into Installing Malware — snyk.io
  46. Glassworm Group: Software Supply-Chain Attackers Disrupted — bankinfosecurity.com
  47. The @antv Ecosystem Was Compromised with Shai-Hulud Malware 300 Packages Affected — ox.security
  48. What is Mini Shai-Hulud npm supply chain attack and was Microsoft and Socket hit by malware? Full explain — economictimes.indiatimes.com
  49. The Miasma worm source code briefly leaked on GitHub — bleepingcomputer.com
  50. Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories — darkreading.com
  51. Miasma supply chain attack: malicious code found in @redhat-cloud-services npm packages — snyk.io
  52. Miasma: Supply Chain Attack Targeting RedHat npm Packages — wiz.io
  53. Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm — aikido.dev
  54. Miasma Worm Supply Chain Attack: 73 Microsoft GitHub Repositories Compromised via AI Coding Tools — rescana.com
  55. Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm — thehackernews.com
  56. Shai-Hulud 2.0 Aftermath: Trends, Victimology and Impact — wiz.io
  57. Active Exploitation Alert: Shai-Hulud Supply Chain Attack Compromises 100 NPM and PyPI Packages with Self-Spreading Malware — rescana.com
  58. Shai-Hulud supply chain attack compromises 323 npm packages — startupfortune.com
  59. GitHub Grafana Labs breaches traced back to TanStack supply chain compromise — helpnetsecurity.com
  60. Hackers have compromised dozens of popular open source packages in an ongoing supply chain attack — tech.yahoo.com
  61. Massive npm Supply Chain Attack Compromises AntV Packages — thecyberexpress.com
  62. s1ngularity: supply chain attack leaks secrets on GitHub: everything you need to know — wiz.io
  63. Typosquatted npm packages used to steal cloud and CI/CD secrets — microsoft.com
  64. Grafana Labs links GitHub environment breach to TanStack npm supply chain attack — cybersecuritydive.com
  65. AntV data visualization tool the latest to be hit by ongoing npm supply chain attacks — infoworld.com
  66. Bitwarden CLI Compromise Linked to Ongoing Checkmarx Supply Chain Campaign — securityboulevard.com
  67. Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack — wiz.io
  68. KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack — wiz.io
  69. JDownloader website compromised to distribute malicious installers — scworld.com
  70. The Nx s1ngularity Attack: Inside the Credential Leak — blog.gitguardian.com
  71. Mini Shai-Hulud Targets SAP npm Packages With a Bun-Based Secret Stealer — aikido.dev
  72. Reconstructing the TJ Actions Changed Files GitHub Actions Compromise — snyk.io
  73. TanStack npm Packages Hit by Mini Shai-Hulud — snyk.io
  74. Compromised Mistral AI and TanStack packages may have exposed GitHub cloud and CI/CD credentials in 'mini Shai Hulud' malware infection supply-chain campaign spreads across npm and AI developer ecosystems like wildfire — tomshardware.com
  75. ShapedPlugin Pro WordPress Plugins Supply Chain Attack: Credential Theft Backdoors and Mitigation Guidance — rescana.com
  76. Attackers compromised Daemon Tools software to deliver backdoors — helpnetsecurity.com
  77. DAEMON Tools Software Hacked to Deliver Malware in a Supply Chain Attack — cybersecuritynews.com
  78. Ensuring comprehensive security testing in DevOps pipelines — snyk.io
  79. Lottie Player npm package compromised for crypto wallet theft — snyk.io
  80. Aikido x Drydock | A way for maintainers to catch malware before it ships — aikido.dev
  81. Hypersonic Supply Chain Attacks: One Solution That Didn't Need to Know the Payload — sentinelone.com
  82. Why Your “Skill Scanner” Is Just False Security (and Maybe Malware) — snyk.io
  83. Securing the Agent Skill Ecosystem: How Snyk and Vercel Are Locking Down the New Software Supply Chain — snyk.io
  84. tj-actions Supply Chain Attack (CVE-2025-30066) - Sysdig — sysdig.com
  85. tj-actions/changed-files Compromised - Semgrep — semgrep.dev
  86. TanStack Supply Chain Attack Hits Two OpenAI Employee Devices Forces macOS Updates — thehackernews.com
  87. SLSA Framework: The Definitive Guide for Securing Your Software Supply Chain — practical-devsecops.com
  88. Supply-Chain Attack Defense: Developer Host Machine Hardening — gist.github.com
  89. NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks — securityweek.com
  90. RubyGems adds dependency cooldown to counter supply chain attacks — news.risky.biz
  91. Pip 26.1 Ships Dependency Cooldowns and Experimental Lockfile Support to Combat Supply Chain Attacks — infoq.com
  92. Practical Package Security: The Unofficial Guide — wiz.io
  93. Supply Chain Cyber Attacks Surge as EU Breach Exposes Weaknesses — cxtoday.com
  94. Do not get high(jacked) off your own supply (chain) — blog.talosintelligence.com
  95. Open Source Security Tool Trivy Hit by Supply Chain Attack Prompting Urgent Industry Response — infoq.com
  96. We hardened zizmor's GitHub Actions static analyzer — blog.trailofbits.com
  97. Supply Chain Attacks Are Getting WorseHow to Shrink Your Exposure — securityboulevard.com
  98. Supply Chain Attacks Surge in March 2026 — securityboulevard.com
  99. 400 Arch Linux AUR Packages Hijacked to Install Rust Credential Stealer — thehackernews.com
  100. UNC1069 Social Engineering of Axios Maintainer Led to npm Supply Chain Attack — thehackernews.com
  101. Why SBOM management is no longer optional — infoworld.com
  102. Axios npm supply chain attack: Malicious updates add remote access trojan — scworld.com
  103. 2026 Supply Chain Security Report: Attack Analysis — bastion.tech
  104. Introducing Package Traffic Controller: Software Supply Chain Security at the Network Edge — jfrog.com
  105. NVIDIA NIM Models Are Now Governed Assets in Your Supply Chain — jfrog.com
  106. The Overlooked Attack Surface: Securing Code Repositories, Pipelines, and Developer Infrastructure — wiz.io
  107. Introducing WizOS: Securing Wiz from the ground up with hardened, near-zero-CVE container base images. — wiz.io
  108. Grafana GitHub Breach Exposes Source Code via TanStack npm Attack — thehackernews.com
  109. Creating SBOMs with the Snyk CLI — snyk.io
  110. Common Threat Matrix for CI/CD Pipeline — github.com
  111. Supply Chain Attacks Target OpenSource Packages — petri.com
  112. Free Compromise Detection for GitHub Repos - Tracebit Community Edition — community.tracebit.com
  113. What We Know About the NPM Supply Chain Attack (Trend Micro) — trendmicro.com
  114. npm v12’s Biggest Security Change: From Implicit to Explicit Trust — jfrog.com
  115. GitHub to Update npm to Thwart Software Supply Chain Attacks — infosecurity-magazine.com
  116. NPM 12 Redefines Script Execution and Dependency Security to Combat JavaScript Supply Chain Attacks — rescana.com
  117. NPM v12 to block supply-chain attacks with new security measures — scworld.com
  118. Following repeated supply chain attacks npm has introduced a 'phased release' system adding a mechanism that prevents packages from being published using only leaked tokens. — gigazine.net
  119. The MCP Security Tool You Probably Need - MCP Snitch — adversis.io
  120. Source Code Leaks Highlight Lack of Supply Chain Oversight — darkreading.com
  121. Supply Chain Campaign Targets SAP npm Packages with Credential-Stealing Malware — wiz.io
  122. TeamPCP Pushes Malicious Telnyx Versions to PyPI, Hides Stealer in WAV Files — thehackernews.com
  123. Mass Supply-Chain Attack Slams npm and PyPi Hits Mistral AI — bankinfosecurity.com
  124. How to Prevent OWASP Software Supply Chain Failures — crossclassify.com
  125. Leaky Vessels: runC and BuildKit container escape vulnerabilities - everything you need to know — wiz.io
  126. Backdoor in XZ Utils allows RCE: everything you need to know — wiz.io
  127. Supply chain attack hits widely-used AI package risks impacting thousands of companies — therecord.media
  128. The XZ backdoor CVE-2024-3094 — snyk.io
  129. Supply chain attack on lottie-player: everything you need to know — wiz.io
  130. Atomic Arch Supply Chain Attack Compromises 1500 Arch User Repository Packages: Credential-Stealing Malware Targets Arch Linux Systems — rescana.com
  131. GitHub Action tj-actions/changed-files supply chain attack: everything you need to know — wiz.io
  132. Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE — unit42.paloaltonetworks.com
  133. Do not pass GO - Malicious Package Alert — snyk.io
  134. GitHub Takes Down 73 Microsoft Repos After Miasma Worm Attack — devops.com
  135. lightning PyPI Compromise: A Bun-Based Credential Stealer in Python — snyk.io
  136. TanStack Npm Packages Compromised Inside The Mini Shai Hulud Supply Chain Attack — snyk.io
  137. Malicious node-ipc versions published to npm in suspected maintainer account compromise — snyk.io
  138. The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised — snyk.io
  139. Laravel Lang Supply Chain Advisory — snyk.io
  140. Four Credential-Harvesting Campaigns Hit Open Source Ecosystems in Two Weeks — blog.gitguardian.com
  141. A year of open source vulnerability trends: CVEs, advisories, and malware — github.blog
  142. Securing the open source supply chain across GitHub — github.blog
  143. Supply Chain Attack Hits 32 Red Hat NPM Packages — securityweek.com
  144. Miasma: Supply Chain Attack Targeting RedHat npm Packages — wiz.io
  145. GlassWorm Malware Takedown: Disruption of Developer Supply Chain Attacks Targeting VSCode npm Python and GitHub — rescana.com
  146. TeamPCP Compromised LiteLLM in AI Supply Chain Attack — esecurityplanet.com
  147. New supply chain attack targets Laravel PHP packages with credential stealer — scworld.com
  148. Why Are Software Supply Chains Under Constant Siege? — paloaltonetworks.com
  149. Megalodon Supply Chain Attack: TeamPCP Compromises 5561 GitHub Repositories via Malicious CI/CD Workflows — rescana.com
  150. Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer — aikido.dev
  151. TanStack npm Supply Chain Attack: Detailed Analysis of the May 2026 GitHub Actions Breach and Multi-Ecosystem Impact — rescana.com
  152. TeamPCP breaches GitHub accessing 3800 internal code repositories — cryptobriefing.com
  153. A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale — wired.com
  154. Grafana Labs Says Code Breach Stemmed from TanStack Attack — infosecurity-magazine.com
  155. More Than 320 npm Packages Targeted in New Shai-Hulud Supply Chain Attack — cxodigitalpulse.com
  156. GitHub links repo breach to TanStack npm supply-chain attack — bleepingcomputer.com
  157. GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension — thehackernews.com
  158. Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft — microsoft.com
  159. Shai-Hulud: What to Know About the Malware Spreading Through Software Pipelines — decrypt.co
  160. GitHub says internal repositories were taken in poisoned VS Code extension attack — cyberscoop.com
  161. Grafana GitHub Breach Linked to TanStack npm Supply Chain Ransomware — cybersecuritynews.com
  162. GitHub Confirms Breach of Internal Repositories Via Malicious VS Code Extension — infosecurity-magazine.com
  163. GitHub Breached: Malicious VS Code Extension Exposes 3800 Repos — dailycoin.com
  164. GitHub Confirms Hack Impacting 3800 Internal Repositories — securityweek.com
  165. GitHub Investigating TeamPCP Claimed Breach of 4000 Internal Repositories — thehackernews.com
  166. OpenAI Hit by TanStack Supply Chain Attack — securityweek.com
  167. The software supply chain is the new ground zero for enterprise cyber risk. Don't get caught short — siliconangle.com
  168. OpenAI confirms exposure in recent Shai-Hulud supply-chain attack — cyberinsider.com
  169. OpenAI Confirms Security Breach Via TanStack npm Supply Chain Attack — cybersecuritynews.com
  170. Active Supply Chain Attack: Malicious node-ipc Versions Published to npm — stepsecurity.io
  171. TanStack Mistral AI UiPath Hit in Fresh Supply Chain Attack — securityweek.com
  172. Checkmarx Jenkins AST Plugin Compromised in KICS Supply Chain Attack — gbhackers.com
  173. Malicious Hugging Face model masquerading as OpenAI release hits 244K downloads — csoonline.com
  174. Sophisticated Quasar Linux RAT Campaign Targets Software Developers in Supply Chain Attacks — cxodigitalpulse.com
  175. North Korean hackers trojanize gaming platform to spy on ethnic Koreans in China — helpnetsecurity.com
  176. Supply-Chain Attacks in an Era of Automation and Implicit Trust — darktrace.com
  177. Quasar Linux (QLNX) A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit PAM Backdoor Credential Harvesting Capabilities — trendmicro.com
  178. Open-source registries hit by 'Mini Shai-Hulud' supply chain attacks — developer-tech.com
  179. Poisoned Ruby Gems and Go Modules Exploit CI Pipelines for Credential Theft — thehackernews.com
  180. SAP NPM Packages Targeted in Supply Chain Attack — securityweek.com
  181. Ongoing supply-chain attack 'explicitly targeting' security dev tools — theregister.com
  182. Bitwarden CLI Impersonation Attack Steals Cloud Credentials and Spreads Across npm Supply Chains — paloaltonetworks.com
  183. Bitwarden CLI Compromised in Shai-Hulud Supply Chain Attack; 334 Developers Exposed — techloy.com
  184. GitHub Actions Abuse Fuels Bitwarden Supply Chain Attack - Open Source For You — opensourceforu.com
  185. Bitwarden NPM Package Hit in Supply Chain Attack — securityweek.com
  186. Checkmarx Supply Chain Attack Exploits Docker Images and CI/CD Pipelines — esecurityplanet.com
  187. Shai-Hulud: The Third Coming Bitwarden CLI Backdoored in Latest Supply Chain Campaign — ox.security
  188. Checkmarx KICS Docker Repo Hijacked in Malicious Code Injection Attack — gbhackers.com
  189. Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain — thehackernews.com
  190. Flaw in Microsoft-owned GitHub repository allowed RCE via issue submission — scworld.com
  191. Axios npm Supply Chain Attack: 83M Downloads Hit — strobes.co
  192. litellm: Credential Stealer Hidden in PyPI Wheel — stepsecurity.io
  193. LiteLLM and Telnyx Compromised on PyPI: Tracing the TeamPCP Supply Chain Campaign — securitylabs.datadoghq.com
  194. Defending Against npm Supply Chain Attacks — Splunk — splunk.com
  195. Multiple Supply Chain Attacks against npm Packages — Red Hat — access.redhat.com
  196. Shai-Hulud Malware: Second-Wave npm Supply Chain Attack — arcticwolf.com
  197. CISA: Widespread Supply Chain Compromise Impacting npm Ecosystem — cisa.gov
  198. Trivy Supply-Chain Attack: Trusted Scanner Compromised Rotate CI/CD Secrets Now — intelligentliving.co
  199. Learnings from Recent npm Supply Chain Compromises - Datadog — securitylabs.datadoghq.com
  200. Shai-Hulud 2.0: Most Aggressive NPM Supply Chain Attack of 2025 - Check Point — blog.checkpoint.com
  201. Most Notable Supply Chain Attacks of 2025 - Kaspersky — kaspersky.com
  202. GitHub Actions Supply Chain Attacks: tj-actions and reviewdog - Hunters — hunters.security
  203. Supply chain dependencies: Have you checked your blind spot? — welivesecurity.com
  204. GitHub Actions Supply Chain Attack: Trivy Breach & Workflow — securityboulevard.com
  205. You Don't Have to Be Hacked to Be Compromised — mexicobusiness.news
  206. npm Supply Chain Attack: debug, chalk, and Beyond — wiz.io
  207. Securing CI/CD After tj-actions and reviewdog Attacks — openssf.org
  208. XZ Backdoor CVE-2024-3094 - JFrog — jfrog.com
  209. GitLab discovers widespread npm supply chain attack — about.gitlab.com
  210. Shai-Hulud Worm Compromises npm Ecosystem — unit42.paloaltonetworks.com
  211. Two different attackers poisoned popular open source tools - and showed us the future of supply chain compromise — theregister.com
  212. 2026 Software Supply Chain Report — sonatype.com
  213. Supply Chain Attacks 2025-2026: Axios, Shai-Hulud, and More — cyberarmy.tech
  214. Inside the TeamPCP cascading supply chain attack — reversinglabs.com
  215. Your developers work for cyber gangs — cyberdaily.au
  216. 12 Months That Changed Supply Chain Security - 2025 Month by Month — silobreaker.com
  217. OWASP Top 10 2025: A03 Software Supply Chain Failures (Beginner's Guide) — authgear.com
  218. Five Key Flaws Exploited in 2025's Software Supply Chain Incidents — infosecurity-magazine.com
  219. Axios NPM Distribution Compromised in Supply Chain Attack — wiz.io
  220. LiteLLM Supply Chain Attack Exposes Credentials Across AI Ecosystems — esecurityplanet.com
  221. Story of Cyberattack: Salesforce Supply Chain Breach — secpod.com
  222. Open Source Developer Intentionally Corrupts His Own Widely-Used Libraries — developers.slashdot.org
  223. Why the Log4j vulnerability is such a big deal according to a former NSA hacker — aol.com
  224. Mitigate Log4j2 / Log4Shell in Elasticsearch — xeraa.net
📚 This guide is synthesized from the full text of resources curated in the Supply Chain library, and refreshed as new material is added.