New research into the Shai Hulud 2.0 supply chain attack reveals a multi-step attack chain that began on November 23, 2025. Attackers used a 'Pwn Request' technique against the asyncapi/cli GitHub repository to exfiltrate GitHub tokens via a malicious fork commit, then deployed a worm through a compromised OpenVSX extension. A

7m read timeFrom aikido.dev
Post cover image
Table of contents
The Unknown WondererSpreading into OpenVSXAppendix - Detailed GitHub timeline

Sort: