<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>Supply Chain Security - Tag - Jun Wen's Blog</title><link>https://junwen7.com/tags/supply-chain-security/</link><description>Supply Chain Security - Tag - Jun Wen's Blog</description><generator>Hugo -- gohugo.io</generator><language>en</language><lastBuildDate>Sun, 30 Aug 2026 00:44:44 -0700</lastBuildDate><atom:link href="https://junwen7.com/tags/supply-chain-security/" rel="self" type="application/rss+xml"/><item><title>NPM Supply Chain Attacks Through a SOC Lens: Blast Radius, TTPs, and Detection</title><link>https://junwen7.com/posts/npm_supply_chain_attacks/</link><pubDate>Sun, 30 Aug 2026 00:44:44 -0700</pubDate><author><name>Jun Wen</name></author><guid>https://junwen7.com/posts/npm_supply_chain_attacks/</guid><description>&lt;div class="featured-image">
&lt;img src="/images/npm_supply_chain/cover.png" referrerpolicy="no-referrer">
&lt;/div>Shai-Hulud, Axios, Keyv — the endless supply chain incidents kept SOC teams busy. This post steps back to look at npm supply chain attacks through a SOC lens: where a poisoned package actually lands, the TTPs behind the campaigns, and what you can realistically detect with the telemetry you already collect.</description></item></channel></rss>