Mini Shai-Hulud Strikes Again: 317 npm Packages Compromised, by (not on Mastodon or Bluesky):

https://safedep.io/mini-shai-hulud-strikes-again-314-npm-packages-compromised/?ref=frontenddogma.com

#security #npm #dependencies

Mini Shai-Hulud Strikes Again: 317 npm Packages Compromised

A compromised npm maintainer account published 637 malicious versions across 317 packages including size-sensor, echarts-for-react, timeago.js, and hundreds of @antv scoped packages, affecting 15M+ monthly downloads.

SafeDep - Real-time Open Source Software Supply Chain Security