Harden your package manager configs against supply chain attacks.
-
Updated
Jul 15, 2026 - Rust
Harden your package manager configs against supply chain attacks.
A compilation of resources in the software supply chain security domain, with emphasis on open source
Split and distribute your private keys securely amongst untrusted network
A compilation of Software Supply Chain Security resources including initiatives, standards, regulations, organizations, vendors, tooling, books, articles and a plethora of learning resources from the web.
List your dependencies capabilities and monitor if updates require more capabilities.
Scan GitHub Actions Workflow logs for IOCs
A phishing-led npm supply chain attack compromised millions of weekly downloads, but IoCs, detection scripts, and remediation steps can help developers defend fast.
Packj audits pull requests for malicious/risky open-source deps
Checks your files for existence of Unicode BIDI characters which can be misused for supply chain attacks. See CVE-2021-42574
Forensic CLI for AI-era supply-chain attacks: XZ tarball diffs, prompt injection scans, MCP/CLAUDE.md/Cursor config audits. SARIF for GitHub Code Scanning.
New Android supply chain attack surface
Ubel is a fast, cross‑ecosystem security engine that resolves dependencies, generates PURLs, scans them through OSV.dev, and enforces security policies during installation to prevent supply-chain attacks. It works with: PyPI (via ubel-pip), npm (via ubel-npm),and Linux distributions (Ubuntu-based, Debian-based, RHEL, AlmaLinux).
examination of linker behaviors in ELF toolchains
Threat hunting investigation in Splunk - supply chain attack via malicious npm package. TryHackMe Operation: Health Hazard. 335 pts.
A Cargo subcommand that updates dependencies only when their latest stable release has aged past a configurable threshold.
This repository is a security research project demonstrating supply chain attack techniques in the Go ecosystem. It is designed for educational and defensive security purposes only.
PoC backdoor embedded within the C runtime zero
Build a real-time auction app with Flutter and Supabase for live bidding, secure auth, and a polished Material 3 UI
Python script to check if any malicious pip packages listed in a text file have been installed.
Simple, dependency-free Python auditor for the 2026 GitHub TeamPCP VS Code extension breach (Nx Console v18.95.0). Detect malicious extensions in seconds. Assume Breach.
Add a description, image, and links to the supply-chain-attacks topic page so that developers can more easily learn about it.
To associate your repository with the supply-chain-attacks topic, visit your repo's landing page and select "manage topics."