Linking pages
- GitHub - chainguard-dev/ssc-reading-list: A reading list for software supply-chain security. https://github.com/chainguard-dev/ssc-reading-list 3 comments
- Meet Package Hunter: A tool for detecting malicious code in your dependencies | GitLab https://about.gitlab.com/blog/2021/07/23/announcing-package-hunter/ 1 comment
Linked pages
- HackerNoon - read, write and learn about any technology https://hackernoon.com/im-harvesting-credit-card-numbers-and-passwords-from-your-site-here-s-how-9a8cb347c5b5 729 comments
- Python Wheels http://pythonwheels.com/ 412 comments
- http://max.computer/blog/how-to-take-over-the-computer-of-any-java-or-clojure-or-scala-developer/ http://blog.ontoillogical.com/blog/2014/07/28/how-to-take-over-any-java-developer/ 356 comments
- Postmortem for Malicious Packages Published on July 12th, 2018 - ESLint - Pluggable JavaScript Linter https://eslint.org/blog/2018/07/postmortem-for-malicious-package-publishes 326 comments
- notes/Gathering-weak-npm-credentials.md at master · ChALkeR/notes · GitHub https://github.com/chalker/notes/blob/master/gathering-weak-npm-credentials.md 301 comments
- PyPI · The Python Package Index https://pypi.org 269 comments
- How I gained commit access to Homebrew in 30 minutes | by Eric Holmes | Medium https://medium.com/@vesirin/how-i-gained-commit-access-to-homebrew-in-30-minutes-2ae314df03ab 254 comments
- npm | Home https://www.npmjs.com/ 238 comments
- Libraries.io - security & maintenance data for open source software https://libraries.io 77 comments
- Maven Central Repository Search https://search.maven.org/ 23 comments
- Distributing a self-replicating malicious code using NPM | by Gajus Kuizinas | Medium https://medium.com/@gajus/distributing-a-self-replicating-malicious-code-using-npm-cf2bf3209293 22 comments
- Snyk | Developer security | Develop fast. Stay secure. | Snyk https://snyk.io 18 comments
- https://www.owasp.org/images/7/72/owasp_top_10-2017_%28en%29.pdf.pdf 15 comments
- Remote Code Execution on rubygems.org https://justi.cz/security/2017/10/07/rubygems-org-rce.html 13 comments
- Backdoored Python Library Caught Stealing SSH Credentials https://www.bleepingcomputer.com/news/security/backdoored-python-library-caught-stealing-ssh-credentials/ 12 comments
- A Confusing Dependency https://blog.autsoft.hu/a-confusing-dependency/ 11 comments
- Cryptocurrency Clipboard Hijacker Discovered in PyPI Repository | by Bertus | Medium https://medium.com/@bertusk/cryptocurrency-clipboard-hijacker-discovered-in-pypi-repository-b66b8a534a8 9 comments
- Keep your dependencies secure and up-to-date with GitHub and Dependabot | The GitHub Blog https://github.blog/2019-01-31-keep-your-dependencies-secure-and-up-to-date-with-github-and-dependabot/ 3 comments
- Remote Code Execution on packagist.org https://justi.cz/security/2018/08/28/packagist-org-rce.html 3 comments
- Compromised npm Package: event-stream | by Thomas Hunter II | intrinsic | Medium https://medium.com/intrinsic/compromised-npm-package-event-stream-d47d08605502 2 comments
Related searches:
Search whole site: site:link.springer.com
Search title: Backstabber’s Knife Collection: A Review of Open Source Software Supply Chain Attacks | SpringerLink
See how to search.