build2 publishersConfirmed Tensorlake's npm SDK 0.5.144 runs a credential-stealing worm from a preinstall hook at install time, Socket reported. According to Socket's analysis, any secret reachable from a workstation or build runner that installed the release may be exposed.
Reality
- Evidence74
- Adoption20
- Hype gap+5
- Incentives40
- Confidence72
Unit 42 says supply-chain attackers have moved command-and-control into blockchain smart contracts, so one transaction can re-point an entire botnet or worm. Defenders' useful choke points are now developer machines, CI runners and the chain lookup itself.
Reality
- Evidence55
- Adoption45
- Hype gap+15
- Incentives45
- Confidence55
build2 publishersConfirmed September's wave altered more than 500 npm package versions and November's backdoored 796, both by republishing under a fresh version number, which is exactly the thing an exact pin declines to fetch.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence58
build1 publisherOne report GitGuardian says the ChainDrop worm reached 444 npm packages by planting a SessionStart hook in Claude Code and a folderOpen task in VS Code, and the publishing credential it steals is used to republish inside the same session.
Reality
- Evidence45
- Adoption55
- Hype gap+22
- Incentives80
- Confidence42
build1 publisherOne report Anthropic, Sysdig, Unit 42 and GitGuardian describe the same shape of failure, which puts the interesting number on your side of the fence: how long an issued token keeps working after it leaves your control.
Reality
- Evidence27
- Adoption44
- Hype gap+37
- Incentives71
- Confidence57
build1 publisherOne report StepSecurity's first annual report logs 56 confirmed supply chain compromises and says plainly that these are its own alerts. The February change is the finding; explaining it is the hard part.
Reality
- Evidence46
- Adoption42
- Hype gap+16
- Incentives79
- Confidence51
Unit 42 says a worm hidden in more than 400 npm packages read GitHub Actions runner memory for temporary OIDC tokens. An SBOM generated at the end of the build would not have seen any of it.
Reality
- Evidence55
- Adoption62
- Hype gap+18
- Incentives80
- Confidence52