Shai-Hulud npm supply chain attack – new compromised packages detected
jfrog.com | incident | #cloud | #supply-chain | #malware | #credential-theft | #npm | #jfrog | #shai-hulud
Summary
JFrog details Shai-Hulud's second wave: 796 new malicious npm packages with stronger obfuscation and persistence, stealing GitHub, npm, AWS and GCP credentials via a TruffleHog-based stealer.
- Published
- Collected
Skip to content