Dependency Management
August 28, 2026
Supply-chain attacks: package cooldowns and policy checks for npm, PyPI and NuGet
On 4 August 2026, a self-propagating worm called ChainDrop tore through npm. BleepingComputer reported more than 1,300 compromised packages with about two billion monthly downloads between them, including keyv, cacheable, flat-cache and file-entry-ca ...
#supply-chain-security#npm#dependency-management#devsecops#ci-cd
