Skip to content
DevTools Feed
New Releases DevOps & Platform Eng Open Source Cloud & Infrastructure
AI Dev Tools Databases & Backend Frontend & Web Engineering Culture

#supply chain attacks

Terminal screenshot of aegis-scan flagging critical code execution in npm package
Open Source

Rust's Aegis-Scan Catches npm Malware npm Audit Ignores—Here's Why It Matters

You run npm install. 847 packages flood in. One could be swiping your AWS keys right now. Enter aegis-scan, a Rust CLI that actually inspects the code.

3 min read 3 days, 16 hours ago
Nicholas Zakas on Changelog podcast critiquing npm security flaws
DevOps & Platform Eng

ESLint Creator Nicholas Zakas: GitHub's npm Fixes Are Mere Table Stakes

Nicholas Zakas, ESLint's creator, isn't mincing words: GitHub's npm security moves are 'table stakes,' not solutions. One big attack could shatter JavaScript's package empire.

3 min read 4 days, 8 hours ago
Broken CI/CD pipeline leaking credentials under hacker attack
Engineering Culture

790,000 Downloads a Month: TeamPCP Hijacks CI/CD Pipelines at Scale

Telnyx, a Python package pulled 790,000 times monthly, just got weaponized by TeamPCP attackers. It's proof your CI/CD pipeline isn't backend plumbing—it's the front line.

3 min read 4 days, 8 hours ago
Illustration of a locked Kubernetes kubeconfig blocking rogue executables
AI Dev Tools

Kubernetes 1.35 Finally Tames Wild Kubeconfig Executables with Exec Plugin AllowList

Picture this: your kubeconfig quietly firing off a shady script on your machine. Kubernetes 1.35 slams the door with an exec plugin allowlist, handing you god-mode control over credential plugins.

3 min read 4 days, 8 hours ago
Illustration of locked GitHub Actions workflow with shield icon and policy gears
AI Dev Tools

GitHub Actions 2026: Lockfiles and Policies to Bulletproof CI/CD

CI/CD's wild west ends in 2026. GitHub's dropping lockfiles and centralized policies to make Actions secure by default — no more supply chain roulette.

3 min read 4 days, 8 hours ago
GitHub Actions workflow diagram with security locks on npm packages and secrets vault
New Releases

30,000 npm Packages a Day: GitHub's Fight to Stop Supply Chain Poisoning

Every day, 30,000 packages hit npm—hundreds laced with malware. GitHub's cracking down on supply chain attacks starting in Actions workflows.

4 min read 4 days, 8 hours ago
Broken chain link with malware code leaking from a cargo ship in a digital harbor
Frontend & Web

Axios Backdoor Blitz: Why Your Next Build Could Be Lazarus's Playground

Axios — downloaded 83 million times weekly — got backdoored by Lazarus Group. Three hours was enough to infect countless builds. Time to ditch blind trust.

3 min read 4 days, 8 hours ago
DevTools Feed

Ship faster. Build smarter.

Categories

  • New Releases
  • DevOps & Platform Eng
  • Open Source
  • Cloud & Infrastructure
  • AI Dev Tools
  • Databases & Backend
  • Frontend & Web
  • Engineering Culture

More

  • RSS Feed
  • Sitemap
  • About
  • Advertise

Legal

  • Privacy
  • Terms
  • Work With Us

Our Network

The AI Catchup AI & Machine Learning Threat Digest Cybersecurity Legal AI Beat Legal Tech Fintech Rundown Finance & Banking Open Source Beat Open Source Fintech Dose Crypto & DeFi

© 2026 DevTools Feed. All rights reserved.

📬

Stay in the loop

The week's most important stories from DevTools Feed, delivered once a week.

No spam. Unsubscribe any time.

You clearly love Developer Tools news — get it in your inbox

🏠 Home 🔍 Search 🔖 Saved 📂 Categories