Preview image for a blog post

Attackers Subvert Trust: The GHAPPIER Campaign and npm Provenance Abuse

GHAPPIER campaign abuses npm Trusted Publishing via OIDC manipulation, escalating software supply chain risks. CloudSEK analyzed.