Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Shai Hulud and Looking Into the Deep End of Supply Chain Mayhem

Summary

Analysis of the leaked Shai-Hulud npm supply chain worm: credential harvesting, exfiltration via C2 or GitHub, backdooring with stolen npm tokens, and a deadman switch that wipes the home directory.
Published
Collected

original ↗

Related coverage

back