
Quincy Castro
Quincy Castro is Chief Information Security Officer at Chainguard, where he leads the company’s cybersecurity strategy and heads Chainguard’s Security and Technology organization. Encompassing IT, corporate security, product security, and other functions, Quincy’s organization empowers employees with best-in-class technology while helping Chainguard and its customers stay ahead of emerging threats.
Written by Quincy Castro

The keyv and cacheable npm Supply Chain Attack: Inside the Mini Shai-Hulud Campaign
security
AsyncAPI supply chain compromise: npm packages backdoored via GitHub Actions "pwn request" (July 2026)
security
We're putting our security to the test, and we want your help
security
@mastra npm scope takeover: 143 packages backdoored via compromised contributor account
security
Miasma Phantom Gyp npm attack: 57 packages, 286 malicious versions hijack CI/CD pipelines via binding.gyp
security
Chainguard customers safe from Mini Shai-Hulud worm targeting @redhat-cloud-services npm packages with 100K+ weekly downloads
security
5 security myths that Mythos ended (as told by a CISO)
security
Node-ipc compromised: Credential stealer targets package with 500k+ weekly downloads
security
Chainguard artifacts safe from npm supply chain attack targeting SAP developer dependencies with 2.25M+ monthly downloads
security