Jun Wen's Blog

NPM Supply Chain Attacks Through a SOC Lens: Blast Radius, TTPs, and Detection

Shai-Hulud, Axios, Keyv — the endless supply chain incidents kept SOC teams busy. This post steps back to look at npm supply chain attacks through a SOC lens: where a poisoned package actually lands, the TTPs behind the campaigns, and what you can realistically detect with the telemetry you already collect.