Reading List

NPM Supply Chain Attack from Michael Tsai RSS feed.

NPM Supply Chain Attack

GitLab (via Hacker News): Our internal monitoring system has uncovered multiple infected packages containing what appears to be an evolved version of the “Shai-Hulud” malware.Early analysis shows worm-like propagation behavior that automatically infects additional packages maintained by impacted developers. Most critically, we’ve discovered the malware contains a “dead man’s switch” mechanism that threatens to destroy […]