Tag: malicious packages
GitHub and PyPI Bet On Time to Slow Down Software Supply Chain Attacks
GitHub and PyPI are using time as a security control, delaying dependency updates and locking older releases against new file uploads ...
Signed, Attested, and Malicious: The Software Supply Chain Has a Deepfake Problem
A developer pulls a package from a reliable repo. It is signed, has provenance, and has been scanned. And then…it contains malware. That is no longer hypothetical. When the Miasma worm tore ...

