#preinstall-malware

[ follow ]
Information security
fromThe Hacker News
1 day ago

Second Sha1-Hulud Wave Affects 25,000+ Repositories via npm Preinstall Credential Theft

A renewed Sha1-Hulud supply-chain campaign compromises hundreds of npm packages, executes malicious preinstall scripts, registers self-hosted runners, and exfiltrates secrets.
[ Load more ]