As cited
Copy frozen at (site build).
threat intel
Shai-Hulud 2.0 Supply Chain Attack: 25K+ Repos Exposing Secrets
A supply chain attack leveraging malicious npm packages has affected more than 25,000 repositories across approximately 350 users, following the pattern of the original Shai-Hulud campaign. The attack exposes secrets and credentials stored in targeted repositories. Security researchers have identified detection and mitigation strategies for the compromised packages.
Why it matters: Development teams and open-source maintainers must audit their npm dependencies immediately to identify and remove malicious packages before exposed credentials are weaponized against their infrastructure and applications.
- Source published
- First seen by Cybersecurity Tracker