Epic npm mini Shai-Halud attack is astounding

Epic npm mini Shai-Halud attack is astounding

This hack resulted in literally 100’s of packages to be compromised, signed, and shipped via NPM. It then infected end-users systems, stealing credentials and then wiping hard drives if someone tries to remove it. It then tried used those permissions to submit even more infected packages.

It did this via a clever permissions exploit via a github action. Give this a watch.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.