Skip to content
The Nexus
SECURITYAug 4 · 22:07 UTCCYBERSCOOPMatt Kapko

Massive supply-chain attack compromises 440 packages under four hours

An attacker compromised a GitHub maintainer account and injected malicious code into over 440 npm packages within four hours using a self-replicating worm based on the Mini Shai-Hulud repository. The malware targeted credentials and sensitive data, affecting packages like keyv, flat-cache, and file-entry-cache, which are present in 46% of cloud environments.

Nexus surfaces and summarizes. The full story lives at the source.

Mentioned
Spot something wrong with this article?Report a problem →
Forward this
Related Signal

Adjacent reporting

Massive supply-chain attack compromises 440 packages under four hours · The Nexus