
An ongoing supply chain attack dubbed "Shai-Hulud" has compromised hundreds of packages in the npm repository with a self-replicating worm that steals secrets like API key, tokens, and cloud credentials and sends them to external servers that the attackers control.
The post Self-Replicating Worm Compromising Hundreds of NPM Packages appeared first on Security Boulevard.
Jeffrey Burt
Source: Security Boulevard
Source Link: https://securityboulevard.com/2025/09/self-replicating-worm-compromising-hundreds-of-npm-packages/