Another Shai-Hulud variant hits npm packages, worming its way into hundreds of packages.
Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly ...
More than 400 NPM packages have been infected with the Mini Shai-Hulud worm in the ChainDrop supply chain attack.
BSides Las Vegas 2026 spent three days making the case that AI coding tools are supply chain attack targets. ChainDrop, a ...
A self-propagating malware campaign has compromised more than 430 npm packages, exposing software projects linked to dependencies that collectively record about two billion installations each month.
Security researchers have warned of a major new Shai-Hulud-based campaign which has already compromised more than 430 ...
A self-spreading worm poisoned hundreds of npm packages in hours, slipped past provenance checks, hid its controls on Ethereum, and hunted AI-tool keys.
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems ...
The Shai Hulud variant’s blast radius includes several highly popular packages thus far.. Security teams are urged to perform ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results