Connect with us

Community

Self-Replicating Worm Affected Several Hundred NPM Packages, Including CrowdStrike’s

Published

on

[ad_1]

The Shai-Hulud malware campaign impacted hundreds of npm packages across multiple maintainers, reports Koi Security, including popular libraries like @ctrl/tinycolor and some packages maintained by CrowdStrike.

Malicious versions embed a trojanized script (bundle.js) designed to steal developer credentials, exfiltrate secrets, and persist in repositories and endpoints through automated workflows.

Koi Security created a table of packages identified as compromised,…

[ad_2]

Source link

Continue Reading