Phylum Research Team

Phylum Research Team

Hackers, Data Scientists, and Engineers responsible for the identification and takedown of software supply chain attackers.

Loading WASM Extensions

Phylum extensions can load Typescript and run Web Assembly. Enabling the logic of extensions to be built in languages that users are familiar with.

The Unacknowledged Risk of Authors

One of the largest (and most oft ignored) attack surfaces across the software supply chain is also one of the most obvious: package maintainers. While problems around maintainer account compromises are by no means a new

Build Your Own Software Supply Chain Extensions

Phylum has added support for Software Supply Chain Extensions. Adding another layer of automation and customizability for all users.

Phylum's Monthly Malware Report: June 2022 - Don't Believe the Type

Overview June’s Malware Analysis yielded more of what Phylum has been seeing for a while: * NPM is targeted far more heavily than any other package registry. * Frequent use of dependency confusion attacks. * Frequent use of

Hidden Dependencies Lurking in the Software Dependency Network

We are not the only ones with a social network! Much like we form social connections through friendships, software packages form connections to other packages through dependencies, when a package relies on another package to be