The Mini Shai-Hulud worm compromised 323 npm packages through the hijacked “atool” account on May 19, publishing 639 malicious versions. Affected packages include echarts-for-react (1.1M weekly ...
Hulud payload to steal CI/CD secrets from Linux-based automation environments. The malware executes during npm install and ...