"Self-Spreading Worms Are Now Loose Inside the npm Registry"
Future Technology
New article published
Tech
"Self-Spreading Worms Are Now Loose Inside the npm Registry"
Software supply chain attacks used to mean one bad package sitting quietly in a dependency tree, waiting to be pulled into someone's build. This month's npm incident is a different animal. Two self-propagating worms, tracked as Shai-Hulud and ChainDrop, have been tearing through the npm registry by stealing maintainer credentials, republishing infected versions of legitimate packages automatically, and repeating the process on every account they compromise.
You received this because you subscribe to Future Technology.