Self-Replicating Worm Compromising Hundreds of NPM Packages

supply chains, audits, configuration drift, security, supply, chain, Blue Yonder, secure, Checkmarx Abnormal Security cyberattack supply chain cybersecurity

An ongoing supply chain attack dubbed “Shai-Hulud” has compromised hundreds of packages in the npm repository with a self-replicating worm that steals secrets like API key, tokens, and cloud credentials and sends them to external servers that the attackers control.

The post Self-Replicating Worm Compromising Hundreds of NPM Packages appeared first on Security Boulevard.

This article has been indexed from Security Boulevard

Read the original article: