logo

Well-architected best practices for software supply chain security

ID: e819124e-08db-5ea8-8a32-2ada5ceaccf9

STIX ID: report--e819124e-08db-5ea8-8a32-2ada5ceaccf9

Feed Name: AWS Security Blog

Threat Score
75/100

Date Published: 2026-05-26

Date Updated: 2026-05-27

Author: Trevor Schiavone

...
...

**Executive summary:** The report describes a series of active npm supply-chain campaigns (e.g., Shai-Hulud, Chalk/Debug, tea.xyz) where compromised maintainer accounts and malicious packages harvested tokens and credentials to propagate across developer environments and CI/CD pipelines; it highlights detection evidence (MAL-IDs, CVE references), attack TTPs (phishing, credential harvesting, token farming, sleeper packages), and prescribes defense-in-depth mitigations including temporary credentials, artifact signing, centralized dependency management, continuous scanning, logging, and provenance verification.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.