← Front PageDevSecOps Desk
DevSecOps
Leaked Shai-Hulud malware fuels new npm infostealer campaign
Weekend npm package poisoning campaign leveraging leaked malware demonstrates how quickly public exploits translate into active supply chain attacks affecting European development pipelines.
Summary written by editorial AI · Source link below
The Shai-Hulud malware leaked last week is now used in new attacks on the Node Package Manager (npm) index, as infected packages emerged over the weekend. [...]
Continue at the source
Read the full report at BleepingComputerExternal link — opens at BleepingComputer in a new tab.
§
Continue with
More from the DevSecOps Desk
- CHRONO-RESOLUTION: A Dependency Resolution Dataset at Release Points for npm, PyPI, and crates.io Packages20 Jul
- SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts19 Jul
- Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT17 Jul
- VulnHunter: Capital One's agentic AI code security tool17 Jul
- The Prover Is the Judge: Verified Security Software from AI Coding Agents in Ada/SPARK17 Jul