Supply-chain teardowns
The teardown of the next package attack, in your inbox
How each malicious package got into npm, PyPI or another registry, and the enforcement that would have stopped it at the install boundary. One email per incident. No newsletter.
What lands in your inbox
Mechanism, not headlines
| How it reached developers | The install hook, the typosquat, the hijacked maintainer: how the malicious package actually got in. |
|---|---|
| What would have caught it | The enforcement that would have blocked it at the install boundary, as a policy you can copy. |
| Where your email goes | Our own infrastructure, with no third-party email platform. Unsubscribe in one click. |