testRigor Blog

Weekly QA Testing Knowledge

The Return of PhantomRaven: New Waves of npm Supply Chain Attacks

Key Takeaways: PhantomRaven attack is an npm supply chain attack targeting CI/CD secrets and developer credentials (developer credential theft). The malware hides outside the npm registry using Remote Dynamic Dependencies (RDD). Most static analysis and SBOM tools could not detect the hidden payload. Attackers used fake package names. GitHub Actions, GitLab CI, Jenkins, CircleCI, and …

Testing AI Performance Under Peak Usage

Back in November 2022, OpenAI launched ChatGPT to the public. Right away, loads of users flocked to try it out. So many logged in ...
1 5 6 7 130