๐Ÿค–robot.villas
PostsTagsStatsStatusAbout

ยฉ 2025 - 2026 Nat Welch. All rights reserved.

โ† All bots

StepSecurity Blog

@stepsecurity@robot.villas

StepSecurity's software supply-chain security research, threat analysis, CI/CD guidance, and updates to its developer and GitHub Actions security products.

Source: https://www.stepsecurity.io/blog/rss.xml

Homepage: https://www.stepsecurity.io/blog

Follow from your server

Enter the server your account is on. You'll finish following there.

or
Or search your app for@stepsecurity@robot.villas

Don't have an account? Find a server at joinmastodon.org

Posts
100
Followers
0
Following
0

Posts

  • 400+ AUR Packages Hijacked: What the "Atomic Arch" Campaign Means for Supply-Chain Security #CyberSecurity #OpenSource #DevSecOps

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383201

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383201

    Don't have an account? Find a server at joinmastodon.org

    Jun 18, 2026
  • Prevent npm and Python Supply Chain Attacks on Developer Machines with Package Configs #Security #SupplyChain #DevSecOps

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383191

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383191

    Don't have an account? Find a server at joinmastodon.org

    Jun 18, 2026
  • Mastra npm Supply Chain Attack: 140+ Packages Backdoored via easy-day-js Typosquat #Security #SupplyChain #OpenSource

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383181

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383181

    Don't have an account? Find a server at joinmastodon.org

    Jun 18, 2026
  • Microsoft's durabletask PyPI Package Compromised in Supply Chain Attack #CyberSecurity #SupplyChain #DevSecOps

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383256

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383256

    Don't have an account? Find a server at joinmastodon.org

    Jun 9, 2026
  • Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents #CyberSecurity #SupplyChain #AI

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383247

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383247

    Don't have an account? Find a server at joinmastodon.org

    Jun 9, 2026
  • The Hades Campaign: Graph ML PyPI Packages Deploy Cross-Platform Memory Scrapers, AI Analyst Misdirection, and a Wiper Deterrent #CyberSecurity #OpenSource #AI

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383238

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383238

    Don't have an account? Find a server at joinmastodon.org

    Jun 9, 2026
  • Pythagora-io/gpt-pilot Compromised on GitHub - Shai-Hulud Credential Stealer Blocked by Python Linter #Security #OpenSource #DevOps

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383230

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383230

    Don't have an account? Find a server at joinmastodon.org

    Jun 9, 2026
  • New in the Threat Center: Compromised Components, Now Available via API #Security #DevSecOps #SupplyChain

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383221

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383221

    Don't have an account? Find a server at joinmastodon.org

    Jun 9, 2026
  • Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp #CyberSecurity #SoftwareSupplyChain #OpenSource

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383263

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383263

    Don't have an account? Find a server at joinmastodon.org

    Jun 4, 2026
  • Nx Console VS Code Extension Compromised #CyberSecurity #DevSecOps #VSCode

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383309

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383309

    Don't have an account? Find a server at joinmastodon.org

    Jun 2, 2026
  • Dev Machine Guard Now Scans Extensions Across Every Modern IDE #Security #DevOps #SoftwareDevelopment

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383298

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383298

    Don't have an account? Find a server at joinmastodon.org

    Jun 2, 2026
  • Laravel-Lang Supply Chain Attack: Every Tag Across Multiple Composer Packages Rewritten to Steal CI Secrets #Security #SupplyChain #DevSecOps

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383282

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383282

    Don't have an account? Find a server at joinmastodon.org

    Jun 2, 2026
  • Multiple redhat-cloud-services npm Packages compromised #Security #SupplyChain #OpenSource

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383273

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383273

    Don't have an account? Find a server at joinmastodon.org

    Jun 2, 2026
  • Megalodon: Mass GitHub Actions Secret Exfiltration Across 5,500+ Public Repositories #Security #GitHub #DevOps

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383317

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383317

    Don't have an account? Find a server at joinmastodon.org

    May 22, 2026
  • 5 Supply Chain Attacks in 48 Hours: Why Securing One Layer Is Not Enough #CyberSecurity #SupplyChain #DevSecOps

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383326

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383326

    Don't have an account? Find a server at joinmastodon.org

    May 21, 2026
  • Dev Machine Guard Now Supports Windows #Security #DevOps #Windows

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383341

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383341

    Don't have an account? Find a server at joinmastodon.org

    May 20, 2026
  • Dev Machine Guard Now Supports Linux #Security #DevOps #Linux

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383335

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383335

    Don't have an account? Find a server at joinmastodon.org

    May 20, 2026
  • Shai-Hulud: Here We Go Again. Mass npm Supply Chain Attack Hits the AntV Ecosystem #CyberSecurity #SoftwareSupplyChain #Npm

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383351

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383351

    Don't have an account? Find a server at joinmastodon.org

    May 19, 2026
  • Active Supply Chain Attack: Malicious node-ipc Versions Published to npm #Security #SupplyChain #OpenSource

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383381

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383381

    Don't have an account? Find a server at joinmastodon.org

    May 19, 2026
  • Introducing Secure Registry: install-time defense for the npm supply chain #Security #SupplyChain #DevSecOps

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383370

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383370

    Don't have an account? Find a server at joinmastodon.org

    May 19, 2026
  • actions-cool/issues-helper GitHub Action Compromised: All Tags Point to Imposter Commit That Exfiltrates CI/CD Credentials #Security #DevOps #CICD

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383361

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383361

    Don't have an account? Find a server at joinmastodon.org

    May 19, 2026
  • TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Compromises TanStack npm Packages #SupplyChain #Security #OpenSource

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383390

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383390

    Don't have an account? Find a server at joinmastodon.org

    May 12, 2026
  • Announcing Dependabot Configuration Enhancements: Cooldown and Group Support #DevSecOps #GitHub #Security

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383464

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383464

    Don't have an account? Find a server at joinmastodon.org

    May 4, 2026
  • CanisterSprawl: pgserve Compromised on npm: Malicious Versions Harvest Credentials and Exfiltrate to a Decentralized ICP Canister #Security #SupplyChain #Malware

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383457

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383457

    Don't have an account? Find a server at joinmastodon.org

    May 4, 2026
  • TeamPCP Injects Two-Stage Credential Stealer into xinference PyPI Package #CyberSecurity #SupplyChain #Malware

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383450

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383450

    Don't have an account? Find a server at joinmastodon.org

    May 4, 2026
  • Bitwarden CLI Hijacked on npm: Bun-Staged Credential Stealer Targets Developers, GitHub Actions, and AI Tools #Security #SupplyChain #DevOps

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383438

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383438

    Don't have an account? Find a server at joinmastodon.org

    May 4, 2026
  • elementary-data Compromised on PyPI and GHCR: Forged Release Pushed via GitHub Actions Script Injection #Security #SupplyChain #GitHubActions

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383431

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383431

    Don't have an account? Find a server at joinmastodon.org

    May 4, 2026
  • A Mini Shai-Hulud Has Appeared: Obfuscated Bun Runtime Payloads Hit SAP-Related npm Packages #CyberSecurity #SoftwareSupplyChain #BunJS

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383422

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383422

    Don't have an account? Find a server at joinmastodon.org

    May 4, 2026
  • lightning: Obfuscated JavaScript Credential Stealer Bundled in PyPI Wheel #Security #SupplyChain #Malware

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383413

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383413

    Don't have an account? Find a server at joinmastodon.org

    May 4, 2026
  • Shai-Hulud Worm Pivots to Multi-Cloud: intercom-client@7.0.4 Hijacked -- 361,000 Weekly Downloads, AWS, GCP, and Azure Credentials Now in Scope #CyberSecurity #CloudSecurity #DevOps

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383403

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383403

    Don't have an account? Find a server at joinmastodon.org

    May 4, 2026
  • Top 2024 Predictions for CI/CD Security #DevSecOps #CICD #Security

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383491

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383491

    Don't have an account? Find a server at joinmastodon.org

    Apr 12, 2026
  • Introducing StepSecurity Dev Machine Guard: Protecting Developer Machines from Supply Chain Attacks #Security #DevOps #SupplyChain

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383483

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383483

    Don't have an account? Find a server at joinmastodon.org

    Apr 12, 2026
  • Securing Vibe Coding and AI Coding Agents: An End-to-End Approach with StepSecurity #AISecurity #DevSecOps #SoftwareSupplyChain

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383473

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383473

    Don't have an account? Find a server at joinmastodon.org

    Apr 12, 2026
  • StepSecurity's Unified Protection Across the SDLC Infrastructure Threat Framework (SITF) #Security #DevSecOps #SupplyChain

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383570

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383570

    Don't have an account? Find a server at joinmastodon.org

    Apr 9, 2026
  • Cline Supply Chain Attack Detected: cline@2.3.0 Silently Installs OpenClaw #Security #SupplyChain #OpenSource

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383561

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383561

    Don't have an account? Find a server at joinmastodon.org

    Apr 9, 2026
  • hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft, DataDog, and CNCF Projects Hit So Far #CyberSecurity #GitHubActions #AI

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383551

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383551

    Don't have an account? Find a server at joinmastodon.org

    Apr 9, 2026
  • Datadog's DevSecOps 2026 Report Validates What We've Been Building #DevSecOps #Security #CICD

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383541

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383541

    Don't have an account? Find a server at joinmastodon.org

    Apr 9, 2026
  • Dev Machine Guard Is Now Open Source: See What's Really Running on Your Developer Machine #OpenSource #Security #DevOps

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383531

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383531

    Don't have an account? Find a server at joinmastodon.org

    Apr 9, 2026
  • axios Compromised on npm - Malicious Versions Drop Remote Access Trojan #Security #OpenSource #SoftwareSupplyChain

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383523

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383523

    Don't have an account? Find a server at joinmastodon.org

    Apr 9, 2026
  • Behind the Scenes: How StepSecurity Detected and Helped Remediate the Largest npm Supply Chain Attack #CyberSecurity #SupplyChain #DevSecOps

    Boost from your server

    Enter the server your account is on. The post opens there so you can boost it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383510

    Don't have an account? Find a server at joinmastodon.org

    Favorite from your server

    Enter the server your account is on. The post opens there so you can favorite it.

    or
    Or paste this post's address into your app's search:https://robot.villas/users/stepsecurity/posts/22383510

    Don't have an account? Find a server at joinmastodon.org

    Apr 9, 2026
ยซ NewerOlder ยป