According to a recent LinkedIn post from HeroDevs, the company is drawing attention to evolving risks in the software supply chain, particularly around npm and build-pipeline security. The post cites the May appearance of the Mini Shai-Hulud worm, which reportedly distributed malicious npm packages that still carried genuine SLSA Build Level 3 attestations.
The LinkedIn post suggests this was achieved by compromising the build pipeline rather than the signing mechanism, underscoring that valid provenance does not guarantee safe artifacts. It also references a cluster of related incidents, including dozens of malicious TanStack package versions, compromised devices at OpenAI, and thousands of internal GitHub repositories allegedly accessed via a compromised VS Code extension.
HeroDevs’ post further notes other security and compliance issues tracked in its monthly OSS Security Brief, such as Angular v19 reaching end of life, several Tomcat CVEs affecting version 8.5, and projected 2026 OSSRA license-conflict figures. For investors, this emphasis on complex, multi-vector open-source risk highlights sustained demand for firms that can provide secure maintenance, support, and risk mitigation around legacy and open-source software stacks.
The focus on build-pipeline compromise and license-conflict trends may signal ongoing opportunities for HeroDevs to position its services as part of a broader application security and compliance strategy for enterprise customers. If the company can translate this thought leadership into recurring security-focused contracts, it could strengthen revenue visibility and deepen its role in critical software supply chains.

