Shai Hulud 2.0: What the Unknown Wonderer Reveals About the Attackers’ Endgame
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
New research into the Shai Hulud 2.0 supply chain attack reveals a multi-step attack chain that began on November 23, 2025. Attackers used a 'Pwn Request' technique against the asyncapi/cli GitHub repository to exfiltrate GitHub tokens via a malicious fork commit, then deployed a worm through a compromised OpenVSX extension. A
Sort: