
npm Supply Chain Worm Returns After Four-Month Dormancy With Same Malicious Payload
A previously documented Shai-Hulud npm supply-chain worm payload has reportedly reappeared after 111 days of inactivity, using the exact same malicious file linked to the May 19 compromise of hundreds of @AntV package versions. The reactivation raises concerns about registry-level malware detection because the payload’s SHA-256 hash had been publicly identified for months. Researchers detected […]
The post npm Supply Chain Worm Returns After Four-Month Dormancy With Same Malicious Payload appeared first on Cyber Security News.