New Shai Hulud Variant Hits Red Hat npm Packages (opens in new tab)
Researchers said that they found a Red Hat employee's GitHub account had been compromised and was used by threat actors to push malicious orphan commits directly to several repositories.
Read the original article