Shai-Hulud V2 is a threat campaign identified by ThreatLabz that targets the npm supply chain by leveraging malicious npm packages to impact downstream Node.js projects.
Shai-Hulud V2 is a threat campaign identified by ThreatLabz that targets the npm supply chain by leveraging malicious npm packages to impact downstream Node.js projects. Its significance stems from the npm ecosystem's widespread use, which enables broad dissemination of malicious payloads through dependency chains, creating a high-impact supply-chain risk in cybersecurity.
A new wave of the Shai-Hulud malware has compromised nearly 500 npm packages, affecting over 26,000 GitHub repositories. This self-replicating worm, which targets developers' credentials and secrets, has been linked to…