Massive npm Supply Chain Attack Hijacks 40+ Packages to Automatically Steal Developer Credentials
A sophisticated supply chain attack called "Shai-Hulud" has infected over 40 npm packages with self-replicating malware, marking the first worm targeting the JavaScript ecosystem. The attack trojans legitimate packages, steals developer credentials including GitHub, npm, and AWS tokens usi...
