A scary, self -replicating Malwaers have infected NPM packages with over 2 million downloads a week – here is how to stay secure


  • A new supply chain attack compromised at least 187 NPM packages targeting developer secrets across software projects
  • Shai-Hulud Worm seems to steal the credentials of credentials, change packages and spread malware through github actions and the NPM tokens
  • Researchers warn the number of compromised packages are likely to grow

At least 187 malicious NPM packages have been uncovered, part of another large supply chain attack against software developers.

Security researchers from Socket, StepSecurity and Aikido all discovered a running campaign, apparently orchestrated by the same group that targeted NX several weeks ago.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top