Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Shai-Hulud was the best thing to happen to supply chain security

Summary

Aikido's data shows npm Trusted Publishing adoption jumped from roughly 20-50 packages a week to 430 after the 2025 attack wave (S1ngularity, the Debug/Chalk phishing, and the self-replicating Shai-Hulud worm that compromised 700+ packages), though only 25% of top-package download volume is covered yet.

Why it matters

This coverage gives security teams current context for monitoring, validation, and remediation.
Published
Collected

original ↗

Related coverage

back