The Software Supply Chain: Compromised Before You Even Know It
Compromised packages in npm, PyPI, and other open-source ecosystems cause real damage – from backdoors to ransomware. CVE monitoring arrives too late, and whether you were affected is often impossible to say. A look at the problem, and how to at least trace the blast radius.