Supply-chain teardowns

The teardown of the next package attack, in your inbox

How each malicious package got into npm, PyPI or another registry, and the enforcement that would have stopped it at the install boundary. One email per incident. No newsletter.

One email per teardown — only when a real supply-chain incident lands. No newsletter. See our privacy policy.

What lands in your inbox

Mechanism, not headlines

How it reached developers The install hook, the typosquat, the hijacked maintainer: how the malicious package actually got in.
What would have caught it The enforcement that would have blocked it at the install boundary, as a policy you can copy.
Where your email goes Our own infrastructure, with no third-party email platform. Unsubscribe in one click.