/ Resource download
Two malicious packages published a day, five years ago. Now it's two a minute. Your scanners check for known vulnerabilities. They have nothing to say about a hostile package with no CVE, published an hour ago, doing damage on install.
This field guide breaks down the six moves behind the last two years of supply-chain attacks (Shai-Hulud, the npm heist, tj-actions, TeamPCP) and the specific control that stops each one. Plus a reference pipeline, an incident runbook, and a printable checklist mapped to SLSA and NIST SSDF.
