Search Results
Learn about software supply chain security and Endor Labs

Malicious 'Pyronut' Package Backdoors Telegram Bots with Remote Code Execution
The malicious Python package pyronut copies the entire project description and code of the popular pyrogram Telegram framework to pass itself off as the real thing, while silently installing a runtime backdoor that grants the attacker arbitrary Python and shell command execution on every victim's machine.

AI SAST: Combining Agents, Program Analysis, and Rules for High-Confidence Code Security
This whitepaper details Endor Labs' multi-modal approach to AI SAST, leveraging agentic reasoning, program analysis, and advanced rules to eliminate 95% of false positives while surfacing complex logic flaws.

CVE-2025-54313: eslint-config-prettier Compromise — High Severity but Windows-Only
CVE-2025-54313 tracks a supply chain attack on eslint-config-prettier, where four malicious versions of a popular npm library targeted Windows machines with a remote-code execution payload. Learn how it happened and how to stay safe.
Book a Demo
Protect your open source dependencies, secrets, and CI/CD pipelines without slowing down devs.




















.png)





































.png)


.png)









%20Software%20in%20Containers.png)











.avif)
.avif)



.webp)




%20(1).png)
%20(1).png)
%20(1).png)
.png)
.png)

.png)
.png)
.webp)
.png)
.png)
.png)
%20(2)%20(2).png)
%20(1)%20(1).avif)

.png)
%20(1).png)
.png)


%20(1).png)
%20(1).png)

%20(1).png)



.png)

%20(1)%20(1).avif)
%20(1)%20(1).avif)
%20(1).avif)
%20(1).avif)
.avif)
.avif)
%20(1).avif)
.avif)
.avif)
.avif)
.avif)
.avif)
.avif)
.avif)
.avif)
%20(1).avif)
.avif)
.avif)
.avif)
.avif)
.avif)





.avif)

.avif)
.avif)
.avif)

%20(1).avif)
.avif)
%20(1).avif)
.avif)
.avif)
%20(1).avif)
%20(1).avif)
.avif)
.avif)
.avif)

%20(1).avif)
.avif)
.avif)
.avif)
.png)

.avif)
.avif)