For years, software supply chain attacks focused on compromising widely used applications after they had already been deployed. Increasingly, however, attackers are shifting their attention further upstream, targeting the open-source packages developers rely on every day. The latest example arrived when Upwind became the first to identify and publicly report a malicious release of the […]This story continues at The Next Web