๐Ÿšจ A new wave of the Shai-Hulud supply chain attack has hit npm, impacting packages across widely used projects from AsyncAPI, ENS, Postman, PostHog, and Zapier.

Attackers added a malicious preinstall script following account compromise. We will be updating this post as our investigation continues.

socket.dev/blog/shai-hulud-str

0

If you have a fediverse account, you can quote this note from your own instance. Search https://fosstodon.org/users/SocketSecurity/statuses/115604948263144978 on your instance and quote it. (Note that quoting is not supported in Mastodon.)