Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Shai-Hulud npm supply chain attack – new compromised packages detected

Summary

JFrog details Shai-Hulud's second wave: 796 new malicious npm packages with stronger obfuscation and persistence, stealing GitHub, npm, AWS and GCP credentials via a TruffleHog-based stealer.
Published
Collected

original ↗

Related coverage

back