Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The „good news” is that code injections are still widely popular in a form of supply chain attacks.

And this is also our fault, e.g. due to the explosion of dependency hell in npm libraries.

This is probably the best intro to modern supply chain attacks and detection techniques, just shared with my team this week:

https://youtu.be/3pLfkutz1x8

(edit: removed youtube tracking)



Is this an ad? The video is essentially an ad for the vendor's solution that's unrelated to the original post.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: