A known Shai-Hulud npm worm payload has resurfaced after 111 days of inactivity, raising fresh questions about the effectiveness of registry-level malware screening. The May campaign demonstrated how quickly a single compromised maintainer account can turn into a software supply-chain incident. Attackers pushed malicious versions across npm packages, including widely used visualization and frontend dependencies. […]
Read the original article: