< Back to situations

[ORGANIZATION]

Cybersense GmbH

Featured in 1 tracked story · first seen

Situations

[ACTIVE] [TECHNOLOGY] [DE]

npm ecosystem supply chain attacks

2 clusters · 7 sources · last updated

Latest: npm registry targeted by massive malware campaign

A significant software supply chain attack has targeted the npm ecosystem, affecting hundreds of packages. Initial reports identified a wave of the ‘Shai-Hulud worm’ that had infected over 440 packages, including widely