Kayssel - Offensive Security Blog · Jul 25, 2026
Supply Chain Attacks: Owning the Install Step
0Sign in to vote or save
This site does not allow itself to be embedded. You can still read it on the original site — the toolbar below keeps your place in the directory.
Dependency confusion, typosquatting on npm and PyPI, install-script code execution, maintainer account takeover, and the Shai-Hulud self-replicating npm worm
Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.