Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Shai-Hulud: Ongoing Package Supply Chain Worm Delivering Data-Stealing Malware

Summary

Wiz details the Shai-Hulud npm worm — malicious releases harvested secrets with TruffleHog, dumped them to public GitHub repos and self-propagated via stolen npm tokens across 100+ packages.
Published
Collected

original ↗

Related coverage

back