Chainguard Blog
RSS FeedFeatured stories

Building a category: Chainguard named a Leader in the inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security
Gartner names Chainguard a Leader in Software Supply Chain Security, highlighting its secure-by-default approach and market vision.

What it took to reach 1 billion build manifests
Chainguard doubled its container build output in six months. Learn how Factory 2.0 uses AI and reconciliation to rebuild secure software at scale.
Latest updates
security@mastra npm scope takeover: 143 packages backdoored via compromised contributor account
engineeringFaster than the advisory
productThe expanding threat landscape: Chainguard now scans source code for traditional malware and “greyware”
securityMiasma Phantom Gyp npm attack: 57 packages, 286 malicious versions hijack CI/CD pipelines via binding.gyp
securityChainguard customers safe from Mini Shai-Hulud worm targeting @redhat-cloud-services npm packages with 100K+ weekly downloads
engineeringThe hardest fork
security5 security myths that Mythos ended (as told by a CISO)
newsChainguard and Upwind: Secure what you build. Verify what you run.
securityPreparing for Mythos: Practical advice for engineering teams
securityMini Shai-Hulud npm Attack: AntV Ecosystem Compromise (May 2026)
newsBuilding for the AI era: Chainguard partners with Endor Labs
securityNode-ipc compromised: Credential stealer targets package with 500k+ weekly downloads