Phylum
@Phylum_IO
Phylum automates software supply chain security to contextualize risks, block attacks and allow organizations to only use trusted open-source code.
You might like
📢 Breaking news: We’re beyond excited to announce that our malicious package analysis, detection, and mitigation technology has been acquired by @Veracode! Together, we’ll take software supply chain security to the next level. Read more below: veracode.com/press-release/…
Phylum Exclusive Research Report by #CEO, Aaron Bray ⚔️ 2025 Software Supply Chain Security Trends & Predictions: AI, Shadow Application Development and Nation-State Attacks - blog.phylum.io/2025-trends-pr… #phylumresearch #softwaresupplychainsecurity #2025trends #CEOinsights
"In Q3 2024, Phylum identified 465,897 malicious packages in the software supply chain open source ecosystem." Read the latest Evolution of Software Supply Chain Security Report via the Phylum Research Team - blog.phylum.io/q3-2024-evolut… [7 min read] #DevOps #CISO #opensourceecosystem
Q3 2024 Evolution of Software Supply Chain Security Report via the Phylum Research Team - blog.phylum.io/q3-2024-evolut… #malciouspackages #npm #opensourceecosystem #DevOps #CISO #AppSec #acceptableuse #softwaresupplychainsecurity #CybersecurityAwarenessMonth #CyberSecurity
blog.phylum.io
Q3 2024 Evolution of Software Supply Chain Security Report
Software supply chain security faces sophisticated security threats in the open-source ecosystem. Phylum analyzed millions of packages & files. Read more.
🎃 Trick or treat? #Malware authors opted for the former with a series of malicious #npm packages targeting #Puppeteer users in an ongoing #typosquat campaign! blog.phylum.io/supply-chain-s… #nodejs #npm #ethereum #opensource #javascript #cryptocurrency #cybersecurity #infosec
blog.phylum.io
Fake Puppeteer Packages Contain Malware
Ongoing supply chain attack targets Puppeteer users with malicious npm packages.
Subscribe to Phylum Research ⚔️ New Report Coming Soon 🔔 blog.phylum.io/subscribe-to-t… #opensource #techcommunity #opensourceecosystem #softwaresupplychain #devops #CISO #AppSec #acceptableuse #techcommunity #developercommunity
Have you ever had your private #crypto keys stolen? #Malware authors have published forks of the popular Ethers library that exfiltrate private keys & give attackers #SSH access to infected machines. blog.phylum.io/trojanized-eth… #npm #opensource #security #ethereum #cryptocurrency
Phylum For Artifact Repositories and Package Managers blog.phylum.io/phylum-for-art… #opensource #techcommunity #opensourceecosystem #softwaresupplychain #DevOps #CISO #AppSec #acceptableuse #machinelearning #techcommunity #developercommunity
blog.phylum.io
Phylum For Artifact Repositories and Package Managers | Phylum
Vet open-source software packages and block attacks before entering an organization or developer workstation.
🇰🇵☠️ Multiple #NorthKorean state actors continue running #malware campaigns against #npm #developers, stealing credentials and financial assets. blog.phylum.io/north-korea-st… #dprk #moonsleet #contagiousinterview #CyberSecurity #javascript #opensource
In the last 6 months, roughly 70% of new #npm packages were #spam. What does this mean for supply chain security? At Black Hat USA? Find us in Startup City booth SC203! #npmjs #node #javascript #typescript #infosec #opensource blog.phylum.io/the-great-npm-…
Code sneaked into fake AWS downloaded hundreds of times backdoored dev devices arstechnica.com/?p=2037194
We've uncovered #malware hidden in a Microsoft logo JPG, shipping as fake #AWS packages on #npm! 😲 blog.phylum.io/fake-aws-packa… #steganography #opensource #cybersecurity #npmjs #javascript #typescript #SoftwareDevelopment #informationsecurity
Advanced threat actors have not let up on their attacks against the software supply chain. We catalog recent attacks from North Korean state actors in our new blog post! #npm #javascript #typescript #malware #cybersecurity #npmjs blog.phylum.io/new-tactics-fr…
blog.phylum.io
New Tactics from a Familiar Threat | Phylum
North Korean hackers are using a new tactic to target software developers. They create fake copies of legitimate packages to steal cryptocurrency and other sensitive data. See Phylum Research...
Supply chain attacks come in all shapes and sizes. Today Phylum Research discusses its discovery of malicious #jQuery files in #npm. blog.phylum.io/persistent-npm… #javascript #opensource #sbom #js #npmjs #node #CyberSecurity
blog.phylum.io
Persistent npm Campaign Shipping Trojanized jQuery | Phylum
Protect your JavaScript projects. Learn about a persistent campaign targeting npm with trojanized jQuery packages designed to steal form data. See Phylum Research.
#OpenSource libs routinely use polyfill.io. Just bc you arent using the compromised #CDN directly, one of your deps might be. We put together a list of recently released pkgs that ref ! #polyfill #polyfillio #malware blog.phylum.io/a-note-about-p…
blog.phylum.io
A Note About Polyfill | Phylum
Discover the power of polyfills. Learn how these essential tools bridge the gap between modern JavaScript features and older browsers. See Phylum Research.
Credential stealer? ✅ Keylogger? ✅ Cryptocurrency stealer? ✅ Phylum uncovers more malicious #npm packages targeting the #Javascript ecosystem. blog.phylum.io/npm-package-ca… #malware #opensource #bitcoin #cryptocurrency #typescript #software #infosec #cybersecurity
Nothing is safe. A few days ago, Phylum's automated platform identified a malicious package targeting users of the #gulp toolkit. The package drops a remote access tool and other nastiness. blog.phylum.io/sophisticated-… #javascript #malware #npm #typescript #opensource #gulpjs
We've uncovered a package published to #PyPI that is hiding a C2 in a PNG file. This package ships as an improvement to the "requests" library, but actually ships a malicious Go binary! blog.phylum.io/malicious-go-b… #malware #opensource #supplychainsecurity #python #infosec #pip
We've uncovered new #malware packages published to #npm that appear to be an evolution on a previous supply chain attack carried out by nation state backed actors ☠ blog.phylum.io/north-korean-s… #npmjs #javascript #supplychainattack #opensource #infosec
#457: Software Supply Chain Security with Phylum <— latest episode is out! #python cc @mkennedy and Charles Coggins from @Phylum_IO talkpython.fm/episodes/show/…
talkpython.fm
Software Supply Chain Security with Phylum
We've spoken previously about security and software supply chains and we are back at it this episode. We're diving in again with Charles Coggins. Charles works at a software supply chain company and...
United States Trends
- 1. Good Wednesday 21K posts
- 2. #hazbinhotelseason2 35.7K posts
- 3. PancakeSwap BNB Chain 2,166 posts
- 4. ADOR 43.9K posts
- 5. Northern Lights 49.4K posts
- 6. #wednesdaymotivation 3,144 posts
- 7. Hump Day 8,482 posts
- 8. USDT 111K posts
- 9. #huskerdust 9,564 posts
- 10. #HazbinHotelSpoilers 3,919 posts
- 11. StandX 2,441 posts
- 12. Hanni 12.7K posts
- 13. Vaggie 7,017 posts
- 14. MIND-BLOWING 33.8K posts
- 15. #chaggie 5,565 posts
- 16. SPECTACULAR 24.9K posts
- 17. Wike 247K posts
- 18. Carmilla 2,682 posts
- 19. Superb 22.6K posts
- 20. H-1B 41.6K posts
You might like
-
3xp0rt
@3xp0rtblog -
India Stack
@India_Stack -
Red Hat Developer
@rhdevelopers -
Checkmarx
@Checkmarx -
Molly Mielke McCarthy
@mollyfmielke -
Liquibase
@liquibase -
cheqd.io 🆔
@cheqd_io -
Nirmata
@NirmataCloud -
GitGuardian
@GitGuardian -
Teleport
@goteleport -
Nearform
@nearform -
Octopus Deploy
@OctopusDeploy -
Payara
@Payara_Fish -
Aretha
@aretrips -
Cory LaViska
@claviska
Something went wrong.
Something went wrong.