Phylum Research Team
Hackers, Data Scientists, and Engineers responsible for the identification and takedown of software supply chain attackers.
Phylum extensions can load Typescript and run Web Assembly. Enabling the logic of extensions to be built in languages that users are familiar with.
The Unacknowledged Risk of Authors
One of the largest (and most oft ignored) attack surfaces across the software supply chain is also one of the most obvious: package maintainers. While problems around maintainer account compromises are by no means a new
Build Your Own Software Supply Chain Extensions
Phylum has added support for Software Supply Chain Extensions. Adding another layer of automation and customizability for all users.
Phylum's Monthly Malware Report: June 2022 - Don't Believe the Type
Overview
June’s Malware Analysis yielded more of what Phylum has been seeing for a while:
* NPM is targeted far more heavily than any other package registry.
* Frequent use of dependency confusion attacks.
* Frequent use of
Hidden Dependencies Lurking in the Software Dependency Network
We are not the only ones with a social network! Much like we form social connections through friendships, software packages form connections to other packages through dependencies, when a package relies on another package to be