
- Osmond van Hemert — Senior Software Engineer/
- Blog Tags: Software Development, AI, Security & Infrastructure/
- Supply Chain Security/
Supply Chain Security


TanStack NPM Supply Chain Compromise — Postmortem, Attack Vectors, and How to Protect Your Projects
·2143 words·11 mins
A massive npm supply chain attack compromised TanStack, Mistral AI’s client library, and over 170 packages. Here’s what happened, how the attack worked, and the practical steps you should take today to protect your projects.

Supply Chain Malware in PyTorch Lightning — When AI Infrastructure Becomes the Attack Surface
·1190 words·6 mins
A Dune-themed malware campaign targeting the PyTorch Lightning library highlights how AI/ML supply chains are becoming prime targets for sophisticated attacks.

The xz Utils Aftermath — One Year Later, What Have We Actually Fixed?
·1213 words·6 mins
Nearly two years after the xz Utils backdoor shocked the open source world, the supply chain security landscape has changed — but not enough.

Software Supply Chain Security Gets Serious — SLSA and SBOM Adoption Accelerates
·1231 words·6 mins
Supply chain security frameworks like SLSA and SBOM requirements are moving from recommendations to mandates. Here’s what developers need to know about the shifting landscape.

Ultralytics Supply Chain Attack — When Your Dependencies Bite Back
·969 words·5 mins
A supply chain attack on the popular Ultralytics YOLO package highlights the persistent vulnerability of the Python ecosystem’s distribution pipeline.

NPM Supply Chain Attacks — The Problem That Won't Go Away
·1108 words·6 mins
Another wave of malicious npm packages reminds us that JavaScript’s dependency ecosystem remains one of software’s biggest security challenges.

Tech Tariffs and the Software Supply Chain — What Engineers Need to Know
·1120 words·6 mins
New US tariffs on technology imports are sending ripples through hardware supply chains, cloud pricing, and software infrastructure planning.

The tj-actions Supply Chain Attack — Why Your CI/CD Pipeline Is an Attack Surface
·920 words·5 mins
A compromised GitHub Action exposed secrets from thousands of repositories, highlighting how CI/CD pipelines have become prime targets for supply chain attacks.

The Polyfill.io Supply Chain Attack — A Wake-Up Call for CDN Trust
·1056 words·5 mins
The polyfill.io domain was acquired by a Chinese company and began injecting malware into over 100,000 websites, exposing fundamental weaknesses in how we trust third-party CDN dependencies.

The xz Utils Backdoor — Open Source's Worst Nightmare Almost Came True
·934 words·5 mins
A sophisticated supply chain attack via the xz Utils compression library was caught just days before reaching stable Linux distributions.

MOVEit Transfer: The Supply Chain Breach That Keeps Growing
·988 words·5 mins
The MOVEit Transfer vulnerability has now impacted hundreds of organizations worldwide — a stark reminder that managed file transfer tools remain critical and under-secured attack surfaces.