Cloudsmith Blog

Supply chain security
Supply chain security
5 min read

Inside the Mastra npm supply chain attack

On June 17, a typosquatted npm package and stolen contributor credentials gave attackers access to 144 Mastra packages with nearly a million weekly downloads. Here's how the attack unfolded, how the malware evaded detection, and how to protect your pipeline…
Supply chain security
7 min read

The Miasma worm's path of destruction

What started as an exploit in Red Hat’s npm packages has since escalated to a sprawling supply chain disaster, spreading to 73 Microsoft GitHub repos across the most popular environments like Microsoft Azure and Durable Task…
Showing 1 to 12 of 104 results
Keep up to date with our monthly newsletter

By submitting this form, you agree to our privacy policy