| |
Mini Shai-Hulud Strikes Again: 314 npm Packages Compromised
A compromised npm account published 637 malicious versions across 317 packages on May 19, 2026, including popular libraries like echarts-for-react and size-sensor, affecting millions of monthly downloads. The malware uses the same toolkit as a previous SAP compromise and harvests credentials across AWS, Kubernetes, GitHub, npm, and password managers while establishing persistent backdoors through GitHub dead-drops and AI development tools. Affected projects using semantic versioning ranges auto-resolve to the compromised versions, enabling widespread credential theft and supply chain compromise.
Read Full Article →
← More Tech news