tag: supply-chain-security
articles: 3 · beats: 1
latest: July 14, 2026
---
Supply Chain Security
3 Crashtech articles on Supply Chain Security, filed under Development Best Practices, published in July 2026. Every piece is full-text HTML with sources, structured data and an authored FAQ.
All 3 sit in the Development Best Practices beat. Development Best Practices
A Misconfigured GitHub Action Backdoored Packages With 3M Weekly Downloads
A pull_request_target flaw in AsyncAPI's CI let attackers steal a token and trojan 4 npm packages — 3M+ weekly downloads — with credential-stealing code.
npm's Biggest Security Overhaul in 16 Years Is Here — Attackers Are Already Adapting
npm v12 blocks install scripts, Git dependencies, and remote sources by default. Researchers say attackers are already routing around it.
One Vendor Flaw Just Exposed 14.2 Million Logins Across Six Japanese ISPs
A flaw in one unnamed vendor's software let attackers into a shared email platform, exposing up to 14.2 million accounts across six Japanese ISPs.
Questions we answer about Supply Chain Security
- What GitHub Actions vulnerability did the attacker exploit?
- How many npm packages were compromised, and how widely were they used?
- What did the malicious payload actually do?
- Why wasn't this vulnerability fixed before the attack happened?
- Does blocking npm install scripts stop this kind of attack?
- What does npm v12 actually change by default?
- Why is npm making this change now, in July 2026?
- Does npm v12 stop supply-chain attacks entirely?
- What happens to CI/CD pipelines that rely on install scripts?
- How are attackers already adapting to npm v12?
Covered alongside
Frequently asked questions
What does Crashtech publish about Supply Chain Security?
3 articles tagged Supply Chain Security, the most recent published July 14, 2026. All 3 sit in the Development Best Practices beat. Each carries numbered sources, an authored FAQ and full structured data.
What questions about Supply Chain Security does Crashtech answer directly?
10 questions have a dedicated answer page under this tag, including “What GitHub Actions vulnerability did the attacker exploit?”. Each answer is authored prose from the article it belongs to, not a generated summary.
Can AI assistants read Crashtech's Supply Chain Security coverage?
Yes. Crashtech serves full static HTML to every crawler, allows all major AI user agents in robots.txt, and publishes an llms.txt manifest plus a full-text corpus, so assistants can retrieve and cite these articles directly.