NEOMSA ESB Release Strengthens Supply Chain Security Through SBOM and Dependency Hardening
NEOMSA ESB is a domestic on-premise integration platform based on Apache Camel and the Camel Karavan project. It provides a visual designer for integration routes while preserving the ability to edit generated YAML routes manually, store them in Git, and review them as code.
The platform includes a web-based designer, a Quarkus backend, a VS Code extension, and a catalog of components and Kamelets. It targets typical enterprise integration scenarios involving accounting, reporting, CRM, ERP, and industry-specific ABS/MES systems.
Why Dependency Composition Represents a Separate Risk Contour
An ESB acts as a central concentration point for data flows between processing systems, ERP, MES, CRM, anti-fraud, and regulatory reporting. Compromise of the bus therefore grants influence over the entire integration perimeter rather than a single application. Sensitive payment details and personal data transit through the bus memory even when they are not stored there.
Integration layers are deployed for years, while libraries age faster than platform releases. Apache Camel alone contains hundreds of components, so even limited usage results in a wide attack surface in the final build.
Automated Release Verification Process
Builds are fully automated. Every pipeline run performs the following steps:
- Generation of an SBOM in CycloneDX format stored as a pipeline artifact.
- SCA analysis using Grype on the SBOM and OWASP Dependency-Check on the repository tree, including frontend lock files.
- SAST with SonarQube and Semgrep using offline rule sets.
- Secret scanning with Gitleaks across the repository and commit history.
- Aggregation of all findings into DefectDojo for deduplication and SLA tracking.
Images are built with Kaniko and tagged with the short commit hash, ensuring full traceability from artifact to source code.
Vulnerability Remediation Approach
The guiding rule is to raise each component only to the minimum version that resolves the reported advisory, not to the latest available release. This principle avoids unintended changes to default settings, function behavior, or removal of legacy methods.
For transitive dependencies, forced version overrides with exact pinning are applied. When multiple major branches of the same package coexist, overrides are defined separately for each branch.
Several non-trivial cases required manual engineering decisions:
- postcss 7.x had no patch; the consuming resolve-url-loader package was upgraded, removing the vulnerable branch entirely.
- The lodash advisory listed 4.17.23 as the last vulnerable version, yet 4.17.24 did not exist; after testing, 4.18.1 was selected following maintainer guidance against 4.18.0.
- An update to a browser-support library altered compilation targets and broke a downstream package; the target set was adjusted to prevent the problematic transformation.
- A lock file contained mismatched version, download URL, and checksum fields; a new verification step now checks all 5,866 lock-file entries for consistency.
Results and Platform Migration
After remediation the build showed zero Critical and High vulnerabilities. The remaining 59 Medium and 53 Low findings were documented in DefectDojo. Most belonged to build tools rather than runtime components.
Accumulated data demonstrated that point fixes had reached diminishing returns on the aging frontend build tooling. The team therefore migrated the fork to Camel Karavan 4.18, which uses Vite. The total package count dropped from 5,872 to 1,683, and the main interface contour shrank from 1,641 to 598 packages.
The same SBOM, scanning, and verification process continues for every build, ensuring the improved composition remains under control for customers.
Related articles
Security Researcher Builds SAST Scanner for AI-Generated Code and Audits 3,800 Public Repositories
A developer released AigisSAST, a lightweight open-source static analysis tool written in pure Python with no external dependencies, specifically tuned to detect common mistakes made by AI coding assistants. The scanner was run across roughly 3,800 repositories ranging from small pet projects to popular open-source platforms. It identified thousands of potential secrets and misconfigurations, yet manual review reduced the number of genuine leaks to approximately 30 cases, mostly Telegram bot tokens, database credentials, and committed .env files. The project also examined 471 production-grade Telegram bots handling payments and VPN services, uncovering 31 repositories that exposed real credentials either in current code or in Git history. AigisSAST includes 21 detection rules, 193 regression tests, automatic remediation via the fix command, and seamless integration with GitHub Actions. The author deliberately avoided validating any discovered keys to stay within ethical research boundaries.
Vendor Responsibility in Open Source: Licensing Obligations Exposed by Sonatype Nexus Changes
The article examines how vendors building products on copyleft open source projects like Nexus Repository OSS inherit significant legal and security responsibilities under licenses such as EPL 1.0. Sonatype's February 2025 shift from regular OSS binary releases to a limited Community Edition forces downstream vendors to handle their own builds, patch porting, and compliance disclosures. This change highlights the second part of copyleft licenses that outlines obligations for distributors, including revealing modifications and assuming liability for the final product. Security implications arise because critical vulnerabilities in the upstream project must now be tracked and patched by the vendor, with delays creating measurable supply chain risks. The piece provides a practical checklist for buyers to assess licensing hygiene, SBOM availability, and vulnerability response times in any open source-based solution.
PhantomSub Campaign Deploys 101 Malicious npm Packages to Hijack WhatsApp Accounts for Unauthorized Channel Subscriptions
Researchers at OX Security uncovered 101 malicious npm packages tied to the PhantomSub campaign that abuse connected WhatsApp accounts to subscribe users to promotional channels without consent. The packages disguise themselves as modified versions of the open-source Baileys library used for WhatsApp automation. Attackers rely on authenticated sessions rather than simple package installation, allowing them to control subscriptions through lists stored on GitHub, in plaintext, or as encoded identifiers. The packages have accumulated roughly 490,000 downloads, including 116,000 in the past 30 days, though the exact number of compromised accounts remains unknown. As of 28 September, npm had removed only 16 of the identified packages. The operation ultimately benefits channels selling bots, game resources, accounts, and promotion services by inflating subscriber counts while disabling notifications to hide the activity.
AI Model Hallucinations Fuel Slopsquatting Attacks on PyPI and npm Registries
Researchers identified 139 package names consistently hallucinated by five different AI models across Python and JavaScript ecosystems. Seven of these names are already registered on PyPI and npm, including one previously used to distribute malware. The attack vector, termed slopsquatting, allows attackers to register AI-suggested package names and execute code with developer privileges during installation. One package, metro-evaluator, contained malicious code removed by npm in December 2025, while another empty package css-color-stop began receiving downloads after the list was published. Real projects such as odf and lusid now occupy names that AI models recommend, causing developers to install unrelated software. Studies show hallucination rates between 4.62% and 21.7% depending on the model, with commercial models performing better than open-source ones. The findings highlight risks when AI coding agents execute dependency installation commands without human verification.