ended5월 21일· 1 sources
Mini Shai-Hulud가 다시 공격: npm 패키지 314개 침해
Why it matters
This represents a critical npm supply chain compromise affecting 314+ packages with 637 malicious versions exploiting semantic versioning resolution to automatically propagate to dependent projects. The sophisticated attack harvests credentials across CI/CD platforms (GitHub Actions, Jenkins, GitLab CI) and cloud infrastructure (AWS, Kubernetes, Vault), enabling attackers to extract sensitive tokens and keys at scale while leveraging GitHub as a C2 channel.
1
Sources
+0
24h
—
Growth
123d
Active
npm supply chaincredential theftBun obfuscationCI/CD abusesemver exploitationMini Shai-Hulud