For an attacker, the software supply chain is a simple path towards compromising #developers & #engineers. At @phylum most of the #malware we see in #opensource registries is targeting #developers and the orgs they work for - to devastating effect.
Phylum automatically detects and blocks software supply chain attacks originating from open-source package registries: npm, PyPI, Rubygems, Crates.io, Nuget, Maven and Go.
Follow for research on supply chain attacks, malicious packages, and security shenanigans.
| Website | https://phylum.io |
| Github | https://github.com/phylum-dev |
| https://twitter.com/Phylum_IO | |
| https://www.linkedin.com/company/phylum-io/ |