Shai-Hulud Malicious Package Campaign Targets Developer Toolchains
Shai-Hulud is a self-propagating malicious package campaign that spread through developer toolchains in 2026, highlighting the need for supply chain security to…
Shai-Hulud is a self-propagating malicious package campaign that spread through developer toolchains in 2026, highlighting the need for supply chain security to…
The npm package atomic-lockfile@1.4.2 was used in the Atomic Arch campaign to deliver the deps payload via a preinstall hook. It was…
The npm package js-digest was used in a second wave of the Atomic Arch attack, delivered via bun install. It contained a…