>_ Posts
Blog
Thoughts on development, engineering, and product.
2 posts
- 01|
Two attacks in four days, a package with 15,000 weekly downloads, and npm v12 arriving to try to stop the bleeding
Injective SDK and Jscrambler were compromised in July 2026, fitting the same pattern that already hit Axios, Red Hat, and node-ipc this year. npm v12, expected this month, promises to end automatic install scripts — but experts say that doesn't fix the real problem.
- 02|
SaaS is eating the world — and tearing open just as many holes
The global SaaS market hit $299 billion and the average company runs 371 cloud applications. Meanwhile, 2026 is shaping up as the year of SaaS supply chain attacks — and the preferred entry point isn't the firewall anymore, it's an OAuth token from an integration nobody has reviewed in months.