Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised
1106 by jamesberthoty | 910 comments on Hacker News.
A lot of blogs on this are AI generated and such as this is developing, so just linking to a bunch of resources out there: Socket: - Sep 15 (First post on breach): https://socket.dev/blog/tinycolor-supply-chain-attack-affect... - Sep 16: https://socket.dev/blog/ongoing-supply-chain-attack-targets-... StepSecurity – https://ift.tt/jx7tc05... Aikido - https://ift.tt/kCzFTbW... Ox - https://ift.tt/vQTk4h9... Safety - https://ift.tt/yhFCdL5 Phoenix - https://ift.tt/CRHsE6e Semgrep - https://ift.tt/t6hZvkx...