“Don’t just grab random stuff off the internet”: What Chainguard found in 52,000 open-source packages (opens in new tab)
Chainguard's new scanner blocks "greyware" — open source packages that pass every security check but still steal credentials, harvest API keys, and phone home to remote servers.
Read the original article