Cybersecurity firms StepSecurity and SafeDep have warned of an ongoing supply chain attack campaign dubbed 'Mini Shai-Hulud' targeting popular open source npm packages. Hackers compromised a developer account and released over 630 malicious package versions across 317 packages in roughly 20 minutes, including Alibaba's Antv library. The malware aims to steal credentials from password managers and other services. The campaign previously compromised the TanStack library, leading to the infection of computers belonging to OpenAI employees.
361 Impressions