Live Updates: Shai-Hulud, the Most Dangerous NPM Breach in History
koi.security·3w·
Discuss: Hacker News

September 16, 2025

We are tracking the largest and most dangerous npm supply-chain compromise in history, known as the Shai-Hulud malware campaign, which has now impacted hundreds of packages across multiple maintainers. This includes popular libraries such as @ctrl/tinycolor as well as packages maintained by CrowdStrike. Malicious versions embed a trojanized script (bundle.js) designed to steal developer credentials, exfiltrate secrets, and persist in repositories and endpoints throug…

Similar Posts

Loading similar posts...