ended5월 12일· 1 sources
Mini Shai-Hulud의 귀환: npm 생태계를 강타한 자가 전파형 공급망 공격 (5/11)
Why it matters
The resurgence of the Mini Shai-Hulud worm highlights a critical vulnerability where self-propagating attacks can weaponize even trusted CI/CD pipelines and OIDC-based publishing. This incident underscores that standard security protocols like SLSA provenance are insufficient if developer secrets are compromised, necessitating a shift toward more robust credential management and real-time package monitoring.
1
Sources
+0
24h
—
Growth
132d
Active
Mini Shai-Huludnpmsupply chain attackCI/CD pipelineTanStackself-propagation