Daily Supply Chain Report
April 21, 2026 - Tuesday
This day, we bring together the 2 key events that entered the chronology, in date order.
Worm-like supply chain attack on NPM: malicious code in 16 Namastex packages. Reported by Socket and StepSecurity; the attack targets SSH, K8s, LLM tokens and MetaMask/Phantom wallets, going cross-platform via PyPI.
In the same period, Lufthansa cancels 20,000 flights over the Iran war. The German carrier is cutting capacity to save 40,000 tonnes of jet fuel.