ShadowPad Attack Exploits WSUS Vulnerability Affecting 25K+ npm Repos
First seen 7 Dec 2025, 20:47 UTC
•
•29
Export
Article Content
Browse articles
The ShadowPad malware attack has exploited a remote code execution vulnerability (CVE-2025-59287) in Windows Server Update Services (WSUS). This incident has exposed over 25,000 npm repositories, allowing cyber threat actors to target users of messaging applications. Morphisec has reported that the attack is linked to Russian cyber operations.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Checkmarx Jenkins Plugin Compromised by TeamPCP Malware Attack
Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages
Shai Hulud npm Worm Compromises Over 26,000 Repositories
OpenAI Faces Supply Chain Attack via TanStack npm Library
Shai-Hulud 2.0 Malware Worm Targets Node Package Ecosystem
Shai-Hulud 2.0 Supply Chain Attack Targets Cloud Ecosystems