ended5월 21일· 1 sources

Mini Shai-Hulud가 다시 공격: npm 패키지 314개 침해

Why it matters

This represents a critical npm supply chain compromise affecting 314+ packages with 637 malicious versions exploiting semantic versioning resolution to automatically propagate to dependent projects. The sophisticated attack harvests credentials across CI/CD platforms (GitHub Actions, Jenkins, GitLab CI) and cloud infrastructure (AWS, Kubernetes, Vault), enabling attackers to extract sensitive tokens and keys at scale while leveraging GitHub as a C2 channel.

1
Sources
+0
24h
Growth
123d
Active
npm supply chaincredential theftBun obfuscationCI/CD abusesemver exploitationMini Shai-Hulud

Sources

Related Issues