
- A new supply-chain attack compromised at least 187 npm packages, targeting developer secrets across software projects
- Shai-Hulud worm looks to steal credentials, modify packages, and spread malware through GitHub Actions and npm tokens
- Researchers warn the number of compromised packages is likely to grow
At least 187 malicious npm packages have been uncovered, part of a yet another major supply-chain attack against software developers.