Shai-Hulud npm supply chain attack – new compromised packages detected
Recently, the npm ecosystem has faced its third large-scale attack. Following the recent compromise of the nx packages and another wave targeting popular packages, the registry has once again been attacked. The first report came from Daniel Pereira, who identified a compromised package: @ctrl/tinycolor@4.1.1. By the end of the day, JFrog’s malware scanners had identified …