Shai-Hulud: npm gets a self-replicating worm
A payload that steals credentials and then uses them to publish itself into other packages. This is the escalation everyone predicted.
tech, developers, and the code underneath
4 pieces tagged npm,
from February 12, 2025 to September 16, 2025.
A payload that steals credentials and then uses them to publish itself into other packages. This is the escalation everyone predicted.
A phishing email to a maintainer, eighteen packages, and a crypto-stealing payload in the browser.
A popular build tool's npm packages ship a payload that harvests tokens and pushes them to public repos.
A practical model for supply chain risk that doesn't require pretending you read 40,000 files of transitive JavaScript.