StepSecurity
Related tags:
Posts about npmPosts about cicdPosts about cyberPosts about secrets-managementPosts about securityPosts about github-actions
Shai-Hulud: Here We Go Again. Mass npm Supply Chain Attack Hits the AntV EcosystemCompromised atool npm Account Delivers CI/CD Credential Stealer Across 24 Packages (echarts-for-react package, timeago.js)actions-cool/issues-helper GitHub Action Compromised: All Tags Point to Imposter Commit That Exfiltrates CI/CD CredentialsNx Console VS Code Extension CompromisedIntroducing Secure Registry: install-time defense for the npm supply chainActive Supply Chain Attack: Malicious node-ipc Versions Published to npmMini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Hits the npm EcosystemShai-Hulud Strikes TanStack: A Supply Chain Attack Targeting Millions of React DevelopersTanStack npm Packages CompromisedShai-Hulud Worm Pivots to Multi-Cloud: intercom-client@7.0.4 Hijacked — 361,000 Weekly Downloads, AWS, GCP, and Azure Credentials Now in Scope
All posts from StepSecurity