Information security
fromThe Hacker News
1 day agoSecond Sha1-Hulud Wave Affects 25,000+ Repositories via npm Preinstall Credential Theft
A renewed Sha1-Hulud supply-chain campaign compromises hundreds of npm packages, executes malicious preinstall scripts, registers self-hosted runners, and exfiltrates secrets.