180+ NPM Packages Hit in Major Supply Chain Attack - OX Security
Sandworms in the Supply Chain: The “Shai‑Hulud” npm Credential Theft Overview Attackers slipped malicious code into new releases of a popular open-source color library @ctrl/tinycolor versions 4.1.1 and 4.1.2. The same campaign also trojanized 40+ packages across multiple maintainers. How it spread Installing a compromised package ran code that stole developer/build credentials. With those credentials, attackers could publish malicious updates to…
www.ox.security · OX Security