When Config Became Executable: The Twenty-Year Pattern Behind Supply Chain Attacks
Across event-stream, SolarWinds, xz utils and the 2026 npm worms, the malicious artifact was never in the repository anyone reviewed. Why CVE-based scanning was blind to 100% of documented campaigns, and why AI agent config files are only the newest file that executes without being called code.
- On August 10, 2026
- 0 Comment Read More
