“Recent attacks show that hackers keep using the same tricks to sneak bad code into popular software registries,” writes long-time Slashdot reader selinux geek, suggesting that “the real problem is how these registries are built, making these attacks likely to keep happening.”
After all, npm wasn’t the only software library hit by a supply chain attack, argues the Linux Security blog. “PyPI and Docker Hub both faced their own compromises in 2025, and the overlaps are…








