Cybersecurity research team

1 post
The Streak Continues: Four More Supply Chain Attacks Hit npm and PyPI

The Streak Continues: Four More Supply Chain Attacks Hit npm and PyPI

Between early June and July 14, four more supply chain attacks hit npm and PyPI: a Shai-Hulud worm variant, typosquatted payment SDKs, a stolen publishing token, and a hijacked CI pipeline. Different entry points, one target: the credentials in developer environments and build pipelines.