A self-replicating worm is exploiting GitHub Actions pipelines to publish malicious npm packages, affecting 16 million weekly downloads. The Mini Shai-Hulud campaign, attributed to Team PCP, has compromised AntV, echarts-for-react, and Microsoft's durabletask SDK, highlighting a new supply chain attack vector.

This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned