SBN

Shai-Hulud is Back: Maintainer Accounts Are Still the Soft Target

The post Shai-Hulud is Back: Maintainer Accounts Are Still the Soft Target appeared first on 2024 Sonatype Blog.

Why bother hunting for a CVE when you can just publish malicious code straight into the software supply chain? That’s the story behind the latest wave of Shai-Hulud-related npm compromises, which recently hit the Ant Design (AntV) ecosystem and potentially exposed downstream developers to credential theft and remote code execution through trusted packages. Again.

*** This is a Security Bloggers Network syndicated blog from 2024 Sonatype Blog authored by Sonatype Security Research Team. Read the original post at: https://www.sonatype.com/blog/shai-hulud-is-back-maintainers-the-target