"Shai-Hulud" affected NPM packages are installed (LINUX) again


Shai-Hulud 2.0 doesn't just propagate like a typical trojan – it behaves like a full-blown worm. Once a compromised package is installed, the malware can steal not only npm or GitHub tokens, but also cloud credentials (AWS, Azure, GCP), CI/CD secrets, environment variables, and other sensitive data from developer machines or build systems.

from https://www.theregister.com.

View original post.

Comments

Popular Posts