• Pricing
Log inContact us

Chainguard Containers

Chainguard Libraries

Chainguard VMs

Chainguard OS Packages

Chainguard Actions

Chainguard Agent Skills

Platform

Image Directory

Updated daily

Chainguard Factory

Integrations

Chainguard Guardener

WHY CHAINGUARDBrowse the Image DirectoryBrowse all images

Compliance

FedRAMP

PCI DSS

CMMC 2.0

SOC 2

Use Cases

AI Threat Protection

Golden Images

CVE Remediation

Industry

Technology

Public Sector

Financial Services

FEATUREDBuild safely with AIExplore AI security

Customers

Customer Stories

Chainguard Reviews

FEATURED STORIESAnduril Trusts Chainguard to Innovate at Mission Speed and ScaleRead the story

Learn

Events & Webinars

Supply Chain Security 101

Chainguard Courses

Slack Community

Developers

Documentation

Trust Center

FEATURED EVENT2026 Gartner® Magic Quadrant™ for Software Supply Chain SecurityDownload the report

Company

About Us

Blog

Open Source Leadership

Partners

Newsroom

Careers

WE'RE HIRINGCareers at ChainguardSee open positions
Pricing
Contact usLog in
Subscribe to our newsletter
Quincy Castro

Quincy Castro

CISOChainguard

Quincy Castro is Chief Information Security Officer at Chainguard, where he leads the company’s cybersecurity strategy and heads Chainguard’s Security and Technology organization. Encompassing IT, corporate security, product security, and other functions, Quincy’s organization empowers employees with best-in-class technology while helping Chainguard and its customers stay ahead of emerging threats.

Back to Blog

Written by Quincy Castro

  • The keyv and cacheable npm Supply Chain Attack: Inside the Mini Shai-Hulud Campaign

    security
  • AsyncAPI supply chain compromise: npm packages backdoored via GitHub Actions "pwn request" (July 2026)

    security
  • We're putting our security to the test, and we want your help

    security
  • @mastra npm scope takeover: 143 packages backdoored via compromised contributor account

    security
  • Miasma Phantom Gyp npm attack: 57 packages, 286 malicious versions hijack CI/CD pipelines via binding.gyp

    security
  • Chainguard customers safe from Mini Shai-Hulud worm targeting @redhat-cloud-services npm packages with 100K+ weekly downloads

    security
  • 5 security myths that Mythos ended (as told by a CISO)

    security
  • Node-ipc compromised: Credential stealer targets package with 500k+ weekly downloads

    security
  • Chainguard artifacts safe from npm supply chain attack targeting SAP developer dependencies with 2.25M+ monthly downloads

    security
12

The trusted source for open source

Talk to an expert

©2026 Chainguard. All Rights Reserved.

PrivacyTerms

Products

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsImages DirectoryChainguard FactoryIntegrationsPricing

Solutions

FedRAMPPCI DSSCMMC 2.0SOC 2AI SecurityAI Threat ProtectionGolden ImagesCVE RemediationPublic SectorTechnologyFinancial Services

Resources

Events & WebinarsSupply Chain Security 101Chainguard CoursesDocumentationTrust CenterChainguard Slack Community

Customers

Customer StoriesChainguard Reviews

Company

About UsBlogOpen Source LeadershipPartnersNewsroomCompareCareersLegalSupport

©2026 Chainguard. All Rights Reserved.

PrivacyTerms