This write-up by the Xygeni research team details the most advanced software supply chain attacks observed so far in 2025. It breaks down how threat actors are planting backdoors in trusted packages, targeting CI/CD pipelines, and bypassing basic scanners. Covers both npm and PyPI examples, plus tactics like dependency hijacking and poisoning GitHub workflows. Curious how others are defending against these multi-layered attacks.
fatidevrel•4h ago