Logo
Search
Home
Archive
Login
Sign Up
Logo

supply-chain

CI/CD

+4

Your release pipeline will vouch for malware

Jul 21, 2026

•

4 min read

Your release pipeline will vouch for malware

AsyncAPI's own release pipeline published five npm versions with malware in them, each with valid provenance.

Weekly Recon

Weekly defensive engineering for cloud, CI/CD, agents, Kubernetes, and software supply-chain security. One attack walked through. One detection idea. One defender move worth shipping.

© 2026 defensive.works Weekly Recon.
beehiivPowered by beehiiv