The BEST way to PROTECT yourself against Supply Chain Attacks @TheAlexLichter
The BEST way to PROTECT yourself against Supply Chain Attacks  @TheAlexLichter
Uploaded September 2025 | Updated September 2026, 9 hours ago
We've seen a huge wave of supply chain attacks in the JS ecosystem (again). This is a real threat to all apps being developed in the JavaScript ecosystem, given that high-download dependencies or tools like Nx are targeted.
This video shows what happened (a high-level overview) and most importantly what YOU CAN DO to protect you and your project against it.

---
Links and Resources

* In the Past: CVEs on Vite youtube.com/watch?v=ctsfEc9UYU8
* Nx got compromised https://www.aikido.dev/blog/popular-nx-packages-compromised-on-npm
* Nx postmortem https://nx.dev/blog/s1ngularity-postmortem
* S1ngularity attacked again https://www.aikido.dev/blog/s1ngularity-nx-attackers-strike-again
* Tinycolor supply chain attack https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages
* Trusted publishing is enabled https://github.blog/changelog/2025-07-31-npm-trusted-publishing-with-oidc-is-generally-available/
* Npm docs on trusted publishing docs.npmjs.com/trusted-publishers
* Npm top packages with provenance status github.com/sxzz/npm-top-provenance#untrusted-showing-first-100-of-8784
* Kevin's post on high-download packages without trusted publishing https://bsky.app/profile/sxzz.dev/post/3lydmji6nr22k
* e18e issue to promote trusted publishing github.com/e18e/ecosystem-issues/issues/201
* Wes' comment on 2FA https://bsky.app/profile/notwes.bsky.social/post/3lwgx6llchc2o
* Daniel Roe's GitHub Action github.com/danielroe/provenance-action
* Old Nuxt opencollective script github.com/nuxt-contrib/opencollective
* PNPM never built dependencies setting pnpm.io/settings#neverbuiltdependencies
* PNPM 10.16 release blog pnpm.io/blog/releases/10.16

---
Chaptermarks

00:00 Intro & Overview
00:59 What has happened - a top-level recap
03:44 What maintainers and package authors can do
06:10 Do we need 2FA for publishing packages?
07:21 How you can protect yourself against these attacks

---

Links marked with * are affiliate links. I get a small commission when you register for the service or buy the product through my link. This helps me keeping the channel running. I only include affiliate links for services or product mentioned that we use ourselves or have good experience with.
The BEST way to PROTECT yourself against Supply Chain AttacksWhich plugins SLOW YOUR BUILD? You can find out now!Nuxt 4 - An overview!Nitro v3 ALPHA: The first lookPrerendered Nuxt sites with LESS JAVASCRIPT?Nuxt vs Nuxi?! What is the correct Nuxt CLI and why.Avoid a common Vue PERFORMANCE KILLERUsing a `src` folder in Nuxt 4
Alexander Lichter |

The BEST way to PROTECT yourself against Supply Chain Attacks

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER