New Shai-Hulud–like npm Worm Attack 19+ Packages to Steal dev/CI Secrets

A new supply chain worm is actively targeting the npm ecosystem, with a research team identifying at least 19 malicious npm packages designed to steal developer and CI/CD secrets and automatically spread across repositories and workflows. The campaign, tracked as SANDWORMMODE, uses typosquatted npm packages and poisoned GitHub Actions to infect both developer machines and […]

The post New Shai-Hulud–like npm Worm Attack 19+ Packages to Steal dev/CI Secrets appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: