Shai-Hulud npm Worm: Self-Spreading Attack Abuses GitHub Actions to Trojanize Dependencies and Steal Secrets
Security researchers have reported a large-scale compromise of more than 180 npm packages by a self-replicating malware strain that automatically trojanizes downstream projects and targets developer secrets. The campaign, dubbed Shai-Hulud, takes its name from a malicious GitHub Actions workflow file shai-hulud.yaml dropped into victim repositories. Some packages tied to a CrowdStrike-associated account were impacted; … Read more