Phylum Research Team

Phylum Research Team

Hackers, Data Scientists, and Engineers responsible for the identification and takedown of software supply chain attackers.

The Great npm Garbage Patch

Open-source spam is a growing threat. The Tea protocol and npm are taking action, but the problem persists. Our research is dedicated to combating this issue and protecting the integrity of the open-source ecosystem. See Phylum Research.

Q2 2024 Evolution of Software Supply Chain Security Report

In Q2 2024, verified malicious package publications were up with increased obfuscation. Attack sophistication has continued to evolve. See the Phylum Research Team's Quarterly Report.

Fake AWS Packages Ship Command and Control Malware In JPEG Files

Beware of malicious JPEG files. Fake AWS packages sneak command-and-control malware into systems, leaving developers vulnerable to attack for more extended periods. See Phylum Research.

New Tactics from a Familiar Threat

North Korean hackers are using a new tactic to target software developers. They create fake copies of legitimate packages to steal cryptocurrency and other sensitive data. See Phylum Research...

Persistent npm Campaign Shipping Trojanized jQuery

Protect your JavaScript projects. Learn about a persistent campaign targeting npm with trojanized jQuery packages designed to steal form data. See Phylum Research.