Largest npm Attack in History – Updated
September 09, 2025
IMPORTANT UPDATE: Shai-Hulud Returns for a Second Wave (Nov 26, 2025) JFrog continues to track, provide research and document a second wave of the Shai-Hulud Software Supply Chain Attack. Following the initial campaign, threat actors have returned with more advanced tactics, compromising an additional 621 new malicious packages across leading public registries. This new wave …