Go 1.27 ran none of a poisoned module's code on go get, go build or go vet in a replay of npm's August 4 worm, but go test ran it with GITHUB_TOKEN in reach. Go teams still carry exposure through CI test runs, versions that stay cached for good, and bots that edit go.mod.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
JFrog is deprecating Xray's Block Download between April and November 2026 and moving enforcement into Curation, a product licensed per seat. Teams who use Xray as their gate have eight months to fund a replacement.
Reality
- Evidence35
- Adoption45
- Hype gap+35
- Incentives85
- Confidence40
GitGuardian says the ChainDrop worm reached 444 npm packages by planting a SessionStart hook in Claude Code and a folderOpen task in VS Code, and the publishing credential it steals is used to republish inside the same session.
Reality
- Evidence45
- Adoption55
- Hype gap+22
- Incentives80
- Confidence42
Unit 42 says a worm hidden in more than 400 npm packages read GitHub Actions runner memory for temporary OIDC tokens. An SBOM generated at the end of the build would not have seen any of it.
Reality
- Evidence55
- Adoption62
- Hype gap+18
- Incentives80
- Confidence52
The poisoned keyv releases were signed by GitHub Actions and the attestation was accurate. It certified a build whose source had already been taken over.
Reality
- Evidence34
- Adoption46
- Hype gap+18
- Incentives76
- Confidence41
A dev.to post scanned the domains behind the top 5,000 npm packages and found 18 with registration or email-security anomalies. The aggregate numbers matter more than the 18, and the headline overstates both.
Reality
- Evidence24
- Adoption
- Insufficient
- Hype gap+58
- Incentives62
- Confidence30