Zero-day Extensive NPM Package Compromise - Shai Hulud Supply Chain Attack
CYBERSECURITY FEATURED ANALYSIS

Zero-day Extensive NPM Package Compromise - Shai Hulud Supply Chain Attack

SOURCE

Blog RSS Feed | Snyk

DATE

READ

1 min read

A supply chain attack hit the ngx-bootstrap npm package, embedding malware to steal developer credentials. See affected versions (e.g., 20.0.4-6, 19.0.3) and our playbook to contain the threat and rotate compromised …

A supply chain attack hit the ngx-bootstrap npm package, embedding malware to steal developer credentials. See affected versions (e.g., 20.0.4-6, 19.0.3) and our playbook to contain the threat and rotate compromised secrets.