
Mitigating malware in the npm ecosystem with Chainguard Libraries
In a recent analysis, Chainguard Libraries for JavaScript prevented over 99% of malicious npm packages published to the npm registry.
3712 articles

In a recent analysis, Chainguard Libraries for JavaScript prevented over 99% of malicious npm packages published to the npm registry.

Wiz and the leading CSPs are launching one of the largest hacking competitions ever to secure the open-source software powering the cloud ecosystem

Chainguard SVP of Product Patrick Donahue shares why he is excited to join Chainguard and how he plans to help build products developers love.

Bring network context into the Security Graph to enrich cloud visibility and strengthen posture

Master CTFs from beginner to elite hacker in 6 months with this ultimate guide! Discover top competitions, understand difficulty classifications, and strategize your path to success from October 2025 to April 2026.

Chainguard implements Zero Trust principles into everything we do to protect critical infrastructure in the age of open source. See how we do it.

A closer look at LameHug, the Amazon Q Developer Extension compromise, s1ngularity, and PromptLock.

Unified cloud security without compromise, delivering commercial features to sensitive government systems

Urgent security alert: On September 25, 2025, the npm package ‘postmark-mcp’ was compromised, secretly exfiltrating email contents. Learn about the incident timeline, impact, and immediate mitigation steps, including uninstalling, rotating credentials, and scanning with Snyk’s MCP-Scan.

Chainguard Libraries for JavaScript is designed to protect developers and organizations from compromised packages, malicious updates, and registry-based attacks.

Elie Bursztein and Marianna Tishchenko from Google’s Privacy, Safety and Security Team emphasize the importance of using AI to strengthen cybersecurity. At DEF CON 33, they hosted the GenSec Capture the Flag (CTF) event in partnership with Airbus, focusing on human-AI collaboration. Nearly 500 participants engaged, with many using AI tools for the first time. Positive feedback highlighted the effectiveness of AI in cybersecurity workflows. Sec-Gemini, Google’s Cybersecurity AI, received commendations for its utility. The event’s success and community input will guide future improvements.

Announcing the GA of our HCP Terraform connector, featuring new zero-configuration code-to-cloud mapping that traces any cloud risk back to its source.