Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised
1129 by jamesberthoty | 917 comments on Hacker News.
A lot of blogs on this are AI generated and such as this is developing, so just linking to a bunch of resources out there: Socket: - Sep 15 (First post on breach): https://socket.dev/blog/tinycolor-supply-chain-attack-affect... - Sep 16: https://socket.dev/blog/ongoing-supply-chain-attack-targets-... StepSecurity – https://ift.tt/HCZM3zS... Aikido - https://ift.tt/TlRXeEU... Ox - https://ift.tt/sChS26d... Safety - https://ift.tt/sLCcfKW Phoenix - https://ift.tt/CBfDogj Semgrep - https://ift.tt/ebR9EQC...
