A new Shai-Hulud supply chain attack has hit nearly 500 npm packages with a…
Tag:
npm
-
-
Vulnerability
Second Sha1-Hulud Wave Affects 25,000+ Repositories via npm Preinstall Credential Theft
by adminby adminNov 24, 2025Ravie LakshmananCloud Security / Vulnerability Multiple security vendors are sounding the alarm…
-
-
-
OS SecuritySecurity
Worm flooding npm registry with token stealers still isn’t under control
by adminby adminA coordinated token farming campaign continues to flood the open source npm registry, with…
-
-
-
-
-
A malicious npm package named “@acitons/artifact” was found impersonating the legitimate “@actions/artifact” module, directly…
