On May 19, the Mini Shai-Hulud worm compromised one npm maintainer account and pushed 639 malicious versions across 323 packages in under 30 minutes. The compromised account, “atool” (i@hust.cc), ...
Australian authorities have charged two alleged TeamPCP members after software supply chain attacks exposed over 500,000 credentials and at least 300GB of data.
A new cyber threat, the "Shai-Hulud" worm, has compromised the Node Package Manager (npm) ecosystem, which is widely used by organizations for JavaScript development. This attack has resulted in ...
Shai-Hulud now scans 469 locations for credentials across developer environments, CI/CD tooling, cloud configs, and AI tool ...
A new report out today from managed detection and response company Expel Inc. details a newly identified variant of the Shai Hulud malware that is demonstrating how software supply chain attacks are ...
A newly discovered third variant of the Shai Hulud malware is raising fresh concerns about the security of the open-source software supply chain, as researchers warn that the latest version shows more ...
The Shai-hulud self-replicating worm, which targets open source repositories, has reemerged with a new, more dangerous variant. Shai-hulud first emerged in September as self-replicating malware that ...
It’s hard out there to be a touring musician these days. We’ve gone over all the difficulties that bands face when heading out on the road before, from rising costs to venue merch cuts and everything ...
Security experts have warned of a major new secret-stealing worm roaming the npm ecosystem which could affect millions of downstream users. Shai-Hulud first appeared in September, when threat actors ...
Security researchers at Aikido on Sunday uncovered an apparently new Shai Hulud variant, uploaded to npm through a GitHub repository called @vietmoney/react-big-calendar. Shai Hulud is the moniker for ...