GitHub moves to tighten npm security amid phishing, malware plague

Discussion in 'malware problems & news' started by stapp, Sep 23, 2025.

  1. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    29,540
    Location:
    UK
    https://www.theregister.com/2025/09/23/github_npm_registry_security/
     
  2. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    186,231
    Location:
    Texas
    Widespread Supply Chain Compromise Impacting npm Ecosystem
     
  3. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    29,540
    Location:
    UK
    Shai-Hulud worm returns, belches secrets to 25K GitHub repos
    https://www.theregister.com/2025/11/24/shai_hulud_npm_worm/

    List of infected packages so far:-
    https://socket.dev/blog/shai-hulud-strikes-again-v2
     
  4. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,747
    Location:
    U.S.A. (South)
    https://socket.dev/blog/shai-hulud-strikes-again-v2

     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.