A major supply chain attack, dubbed “Shai-Hulud,” is targeting the npm ecosystem through phishing campaigns against maintainers, allowing attackers to compromise accounts and inject self-propagating malware into popular packages. The malicious code, often hidden in bundle.js, scans for and exfiltrates secrets while some variants attempt to expose private repositories and deploy malicious GitHub Actions. With at least 180 and possibly over 500 packages affected, including widely used utilities and vendor libraries, the incident represents one of the most severe threats to the JavaScript ecosystem.
Get through updates and upcoming events, and more directly in your inbox