Malwaere, terrifying and self -replicator, has infected NPM packages with more than 2 million downloads per week, here we show you how to stay safe


  • A new supply chain attack committed at least 187 NPM packages, aimed at developer secrets in all software projects
  • Shai-Hulud Worm seeks
  • Researchers warn that the number of committed packages is likely to grow

At least 187 Malicious NPM packages have been discovered, part of a more important supply chain attack against software developers.

Socket security researchers, Stepsecury and Aikido detected an ongoing campaign, apparently organized by the same group that went to NX several weeks ago.

scroll to top