Join Nostr
2025-09-16 16:47:02 UTC

BleepingComputer on Nostr: Security researchers have identified at least 187 npm packages compromised in an ...

Security researchers have identified at least 187 npm packages compromised in an ongoing supply chain attack. The coordinated worm-style campaign dubbed 'Shai-Hulud' started yesterday with the compromise of the /tinycolor npm package, and has now expanded to CrowdStrike's npm namespace.

https://www.bleepingcomputer.com/news/security/self-propagating-supply-chain-attack-hits-187-npm-packages/