Newsdesk
Engineering
Data & AI
Industries
Enterprise Systems
Go-to-Market
Longform
DesignIndiaAll stories

Open Source

Licences, Governance & Supply Chain. Published every Friday, here and by RSS.

41 stories 7 issues 9 categories

Licensing Governance Forks & Splits Supply Chain Maintainers Foundations Regulation Security Reading

Top stories

RSS
Supply Chain

npm 'Shai-Hulud' Worm Compromises Packages

Security researchers identified an active supply chain attack involving the 'ChainDrop' / 'Shai-Hulud' malware family, which compromised over 1,300 npm package versions, including Keyv and related caching libraries. The malware steals developer credentials and self-propagates by republishing modified packages.

Why it matters — Organizations using Node.js must immediately review dependencies, treat credentials on affected systems as compromised, and remove malicious package versions from all environments.

microsoft.com · 09 August 2026 · Read the original →

Supply Chain

Supply chain attack on arrayref (Rust blog)

A malicious Rust crate named proc-macro1 was uploaded to crates.io, and the popular arrayref crate was republished to depend on it. The registry maintainers intervened by removing the malicious version and restoring the safe versions of arrayref that had been yanked.

Why it matters — Highlights how attackers can compromise the supply chain by republishing popular packages with malicious dependencies, requiring registry-level intervention to restore safe versions.

LWN · 21 August 2026 · Read the original →

Security

Eight stable kernels with fix for a single vulnerability

The Linux kernel maintainers released eight stable kernel versions simultaneously to address a single vulnerability (CVE-2026-80590) that can cause a kernel panic. The vulnerability has been present in the codebase since Linux 2.6.27, affecting long-term stable releases spanning many years.

Why it matters — A single legacy vulnerability can require coordinated emergency releases across nearly a decade of stable branches, illustrating the massive maintenance tail of core open-source infrastructure.

LWN · 28 August 2026 · Read the original →

Supply Chain

Keyv npm Packages Compromised in Attack

A supply chain attack, starting August 4, 2026, compromised widely used npm packages like 'keyv' and 'cacheable' through a GitHub account takeover, injecting a self-propagating credential-stealing worm. This 'Mini Shai-Hulud' variant affected hundreds of packages with over 500 million weekly downloads.

Why it matters — Engineers must audit dependency trees, pin to versions published before August 4, 2026, and rotate all potentially exposed credentials to mitigate the spread of credential-stealing malware.

Snyk · 04 September 2026 · Read the original →

Regulation

Freedom for Hacking!!1

The Software Freedom Conservancy is participating in the triennial DMCA exemptions process to petition for the public's right to circumvent software access controls on their devices. This process aims to claw back digital autonomy and restore user rights over their own technology.

Why it matters — Demonstrates how legal exemptions can bypass DMCA restrictions, allowing developers and users to legally modify and control the software on their physical devices.

Software Freedom Cons. · 28 August 2026 · Read the original →

More committees, more metadata files, and the same unpaid maintainers keeping the lights on.

Weekly editions

Each edition is one week's digest exactly as it was published — a summary of the week, then the stories.