<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Supply-Chain on Blackwell Systems</title><link>https://blog.blackwell-systems.com/tags/supply-chain/</link><description>Recent content in Supply-Chain on Blackwell Systems</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 03 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.blackwell-systems.com/tags/supply-chain/index.xml" rel="self" type="application/rss+xml"/><item><title>We Scanned 300 npm and PyPI Packages for Supply Chain Attacks Without Executing a Single Line of Code</title><link>https://blog.blackwell-systems.com/posts/supply-chain-detection-without-executing-code/</link><pubDate>Wed, 03 Jun 2026 00:00:00 +0000</pubDate><guid>https://blog.blackwell-systems.com/posts/supply-chain-detection-without-executing-code/</guid><description>We indexed 300 popular packages with knowing&amp;rsquo;s code graph, computed isolation scores based on credential access + process spawning patterns, and achieved a 1.0% false positive rate across both the initial 200 and a held-out 100. No sandbox. No execution. No heuristics. Just graph structure.</description></item></channel></rss>