Popular npm Package With 150K Weekly Downloads Compromised in Mini Shai-Hulud Supply-Chain Attack

A JavaScript development package has been caught in a supply-chain compromise that can run malicious code when installed. The incident affects a tool with about 150,000 weekly downloads, risking developer and automated build systems. Attackers published ten tainted releases on August 28 in two bursts. They covered every maintained version line, and a routine dependency […]

This article has been indexed from Cyber Security News

Read the original article: