The Worm in Your Supply Chain: Inside the Shai-Hulud npm Attacks
A self-replicating worm hit 500+ npm and PyPI packages this month — including Red Hat's. It doesn't just poison code; it steals the credentials that let it log in and republish itself everywhere the maintainer has access.
