Charlie Eriksen, a researcher at Aikido, identified the infected libraries and confirmed each detection manually to minimize ...
The latest version also executes malicious code during the preinstall phase, and is bigger and faster than the first wave, ...
A popular JavaScript cryptography library is vulnerable in a way which could allow threat actors to break into user accounts.
"As a new and significantly more aggressive wave of npm supply chain malware, Shai-Hulud 2 combines stealthy execution, ...
A new version of the Shai-Hulud worm has infected hundreds of npm packages and caused disruption to global CI/CD workflows ...
A major JavaScript supply-chain attack has compromised hundreds of software packages — including at least 10 used widely ...