Shai-Hulud Returns: Over 300 NPM Packages infected via Fake Bun Runtime Within Hours https://lobste.rs/s/od61og #javascript #security
https://helixguard.ai/blog/malicious-sha1hulud-2025-11-24
If you have a fediverse account, you can quote this note from your own instance. Search https://mastodon.social/users/lobsters/statuses/115604698595737459 on your instance and quote it. (Note that quoting is not supported in Mastodon.)