Cloudsmith Blog

Featured
Supply chain security
5 min read

Inside the Mastra npm supply chain attack

On June 17, a typosquatted npm package and stolen contributor credentials gave attackers access to 144 Mastra packages with nearly a million weekly downloads. Here's how the attack unfolded, how the malware evaded detection, and how to protect your pipeline…
Supply chain security
7 min read

The Miasma worm's path of destruction

What started as an exploit in Red Hat’s npm packages has since escalated to a sprawling supply chain disaster, spreading to 73 Microsoft GitHub repos across the most popular environments like Microsoft Azure and Durable Task…
Keep up to date with our monthly newsletter

By submitting this form, you agree to our privacy policy