
Shai-Hulud Trinitite Supply-Chain Worm Hits npm Package With 150K+ Weekly Downloads
A new Shai-Hulud supply-chain campaign, tracked as Trinitite, has compromised the npm package @7nohe/openapi-react-query-codegen, which receives more than 150,000 weekly downloads. The malicious versions use a hidden binding.gyp execution path and a large obfuscated JavaScript loader to infect developer machines and CI environments. The campaign appears linked to the previously reported Shai-Hulud “Mini” worm family, […]
The post Shai-Hulud Trinitite Supply-Chain Worm Hits npm Package With 150K+ Weekly Downloads appeared first on Cyber Security News.