Small Bytes

Official ByteBard Blog

The Weekly Dependency Threat Report: 2026-09-12

- 4 min read - Alex Wichmann

This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries. 1. tailwindcss-contact-forms (npm) * Package: https://www.npmjs.com/package/tailwindcss-contact-forms * Severity: critical * Affected versions: 0.5.6 * Downloads: 1417 * First seen: 10 September 2026 at

Continue reading

The Weekly Dependency Threat Report: 2026-09-05

- 10 min read - Alex Wichmann

This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries. 1. @crysnovax/baileys (npm) * Package: https://www.npmjs.com/package/@crysnovax/baileys * Severity: critical * Affected versions: 2.8.3 * Downloads: 4127 * First seen: 4 September

Continue reading

The Weekly Dependency Threat Report: 2026-08-29

- 8 min read - Alex Wichmann

This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries. 1. @hd-team/app-dnpkg-beta (npm) * Package: https://www.npmjs.com/package/@hd-team/app-dnpkg-beta * Severity: critical * Affected versions: all * Downloads: 210389 * First seen: 27 August 2026 at

Continue reading

The Weekly Dependency Threat Report: 2026-08-22

- 11 min read - Alex Wichmann

This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries. 1. matrixflow-js (npm) * Package: https://www.npmjs.com/package/matrixflow-js * Severity: critical * Affected versions: 3.2.1 * Downloads: 1504353 * First seen: 19 August 2026 at

Continue reading

A simple architecture for securing every package

- 4 min read - Alex Wichmann

Modern software supply chains are complicated enough, CI, local developer machines, multiple environments. The system protecting them should not add more complexity than necessary. ShieldedStack's long-running application architecture is built around three clear units: the Portal, the Proxy, and the

Continue reading

The Weekly Dependency Threat Report: 2026-08-15

- 5 min read - Alex Wichmann

This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries. 1. spoint (npm) * Package: https://www.npmjs.com/package/spoint * Severity: medium * Affected versions: 0.1.695-0.1.700 * Downloads: 20346 * First seen: 11 August

Continue reading

The Weekly Dependency Threat Report: 2026-08-08

- 5 min read - Alex Wichmann

This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries. 1. @servicetitan/install (npm) * Package: https://www.npmjs.com/package/@servicetitan/install * Severity: high * Affected versions: 38.1.1, 38.1.2, 38.1.3,

Continue reading