DEV Community

# supplychain

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
161 verified AI package hallucinations across 8.5M indexed — open dataset

161 verified AI package hallucinations across 8.5M indexed — open dataset

Comments
4 min read
Four MCP packages, four ways the supply chain shifted in two weeks of npm monitoring

Four MCP packages, four ways the supply chain shifted in two weeks of npm monitoring

Comments
7 min read
Slopsquatting in Python: What 205,474 Hallucinated Package Names Mean for Your Supply Chain

Slopsquatting in Python: What 205,474 Hallucinated Package Names Mean for Your Supply Chain

Comments
8 min read
I built chainscope: reading supply chain attacks across 6 surfaces, one slide at a time

I built chainscope: reading supply chain attacks across 6 surfaces, one slide at a time

Comments
7 min read
SLSA Provenance Hands-on: Generate with GitHub Actions, Verify with slsa-verifier

SLSA Provenance Hands-on: Generate with GitHub Actions, Verify with slsa-verifier

Comments
11 min read
Why Did Docker Abandon TUF?: A Turbulent History of Container Signing

Why Did Docker Abandon TUF?: A Turbulent History of Container Signing

2
Comments
10 min read
The Anthropic SDK Looks Safe. Two of Its Transitive Dependencies Are Not.

The Anthropic SDK Looks Safe. Two of Its Transitive Dependencies Are Not.

Comments
3 min read
Two Types of npm Supply Chain Attack: What Catches Each

Two Types of npm Supply Chain Attack: What Catches Each

Comments
5 min read
The Dependency Avalanche: 644 Strangers in Your package.json

The Dependency Avalanche: 644 Strangers in Your package.json

Comments
6 min read
572K Weekly Downloads, One Preinstall Script: The SAP CAP Supply Chain Attack Your AI Agent Would Have Missed

572K Weekly Downloads, One Preinstall Script: The SAP CAP Supply Chain Attack Your AI Agent Would Have Missed

1
Comments
3 min read
Continuous monitoring caught a credential leak in a published MCP package. Six republishes later, it is still there.

Continuous monitoring caught a credential leak in a published MCP package. Six republishes later, it is still there.

Comments
7 min read
Supply Chain Attacks Targeting Bitwarden CLI and How to Defend

Supply Chain Attacks Targeting Bitwarden CLI and How to Defend

Comments
5 min read
Vercel OAuth Compromise via Context.ai: Timeline, IOCs, and Remediation

Vercel OAuth Compromise via Context.ai: Timeline, IOCs, and Remediation

Comments
4 min read
The EU Is Forcing User-Replaceable Phone Batteries. There's a Loophole Apple Is Already Using.

The EU Is Forcing User-Replaceable Phone Batteries. There's a Loophole Apple Is Already Using.

1
Comments
4 min read
Slopsquatting: The AI Supply Chain Attack Vector You Are Not Monitoring

Slopsquatting: The AI Supply Chain Attack Vector You Are Not Monitoring

Comments
6 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.