Silent Blight: The Industrialization of Software Supply Chain Attacks
In 2026, supply chain attacks stopped being one-off typosquats and became self-propagating worms — armed with forged SLSA attestations, kernel-level eBPF rootkits, AI-assistant backdoors, and dead-man's switches that wipe your home folder if you revoke the token. A first-person field report on Shai-Hulud, Miasma, Mastra, Megalodon, and Atomic Arch — and how to survive them.
Read more →