Shai-Hulud Malware Attack Compromises Over 1,280 npm Packages
A significant supply-chain attack, known as the Shai-Hulud malware, has compromised over 1,280 npm packages, affecting more than 2 billion monthly downloads. The attack involved hijacking a GitHub account of a key maintainer and publishing malicious updates. The malware executes during npm installs, stealing credentials from systems and spreading to other packages. Researchers from Aikido Security and Endor Labs are tracking the attack, which continues to expand rapidly, infecting new packages every few minutes.