Signed, Attested, and Malicious: The Software Supply Chain Has a Deepfake Problem July 22, 2026 by Nigel Douglas A developer pulls a package from a reliable repo. It is signed, has provenance, and has been scanned. And then…it contains malware. That is no longer hypothetical. When the Miasma […]