Blog

Thinking on software supply-chain security

Analysis of the threat landscape, explainers on the fundamentals, and case studies of the incidents that shaped the field. New to the topic? Start with Supply-Chain Security 101.

Analysis

Analysis and opinion

Where the supply-chain threat landscape is heading, and what it means for how teams respond.

Opinion

Adversaries Are Publishing at Scale. Speed Is Now the Only Defence.

A corpus of roughly 1,000 malicious packages impersonating TanStack libraries surfaced recently via jsDelivr telemetry. It is not an anomaly. It is the new baseline. The only meaningful response is to act faster than the blast radius can spread.

Sim Chiwanza · 20 May 2026 · 5 min read
Opinion

H2 2026: Packages Are the New Phishing Email, and Your Secrets Are the Target

Axios. LiteLLM. TeamPCP. Anthropic's AI adversary report. The first half of 2026 has given us enough signal to make a clear prediction: the second half will be worse. Malicious packages are not a supply chain problem any more. They are a credential theft problem. And most organisations are not set up to respond fast enough.

Sim Chiwanza · 20 May 2026 · 6 min read
Threat Intelligence

Mini Shai-Hulud: The Self-Replicating npm Worm That Should Change How You Think About Dependencies

The fourth campaign in the Shai-Hulud series has arrived. Mini Shai-Hulud targets SAP packages, TanStack and agentic AI libraries with a self-propagating worm that steals credentials, injects malicious code and spreads across your entire CI/CD estate before your scanner has filed a ticket.

Verifi Research Labs · 20 May 2026 · 7 min read
Supply Chain

AI Coding Is Creating Dependency Sprawl

AI coding assistants are transforming how software is built, but they are also quietly flooding enterprise codebases with unvetted dependencies at a scale security teams were never prepared for.

Verifi Research Labs · 2 May 2026 · 6 min read
AppSec

Why Dependency Hygiene Is the New AppSec Backlog

For years, application security teams have wrestled with vulnerability backlogs: thousands of findings, prioritised by severity, worked down slowly by engineering teams. Dependency hygiene is becoming the same problem, at greater scale.

Verifi Research Labs · 19 April 2026 · 5 min read
Orchestration

From Detection to Orchestration in Software Supply Chain Security

The software supply chain security market has spent a decade getting very good at detection. The next decade belongs to orchestration: the operational layer that takes detection signals and turns them into controlled, verified remediation.

Verifi Research Labs · 5 April 2026 · 7 min read
Explainers

The fundamentals

Plain-English explainers on the attacks, defences, and standards that make up supply-chain security.

Explainer

Dependency Confusion, Explained

How a public package can hijack your private one, and how to prevent it.

1 min read
Explainer

How Malicious Packages Hide: Obfuscation Techniques

Base64, eval, packing, and environment gating, the tricks that hide payloads from scanners and reviewers.

1 min read
Explainer

Indicators of Compromise (IOCs) in the Supply Chain

The concrete artifacts, IPs, domains, hashes, wallets, webhooks, that betray malicious packages.

1 min read
Explainer

Known vs Novel Malware in Dependencies

Why matching against known-bad lists isn't enough, and what catching novel threats actually takes.

1 min read
Explainer

Maintainer & Account Takeover

How attackers hijack trusted packages by taking over the people who publish them.

1 min read
Explainer

Malicious Install Scripts

Why install-time code execution is the supply chain's favourite weapon, and how to neutralise it.

1 min read
Explainer

MITRE ATT&CK for the Software Supply Chain

Mapping package attacks to a shared language of tactics and techniques.

1 min read
Explainer

Provenance & SLSA, Explained

Knowing not just what a package is, but how and where it was built.

1 min read
Explainer

Reachability Analysis, Explained

Most "critical" vulnerabilities never run in your app. Reachability tells you which ones do.

1 min read
Explainer

SBOMs, Explained

What a Software Bill of Materials is, why it's now table stakes, and where it stops being useful.

1 min read
Explainer

Secrets in Packages, Leaked and Stolen

Two secret problems in the supply chain, secrets accidentally shipped, and secrets actively stolen.

1 min read
Explainer

Software Supply-Chain Security 101

What the software supply chain is, how it gets attacked, and how to defend it.

1 min read
Explainer

Software Supply-Chain Security FAQ

Common questions about securing open-source dependencies, answered.

1 min read
Explainer

Software Supply-Chain Security Glossary

Plain-English definitions of the terms in supply-chain security, with links to go deeper.

1 min read
Explainer

Typosquatting in Package Registries, Explained

How attackers use look-alike package names to slip malware into your build, and how to stop it.

1 min read
Explainer

VEX, Explained

Vulnerability Exploitability eXchange, the standard way to say "present, but not exploitable here.

1 min read
Explainer

What Is a Registry Firewall?

Stop malicious packages before they're ever installed, by vetting at the registry layer.

1 min read

See how Verifi puts this into practice

The platform turns this thinking into detection, enforcement, and automated remediation across your estate.