Large supply chain attack targeting Node Package Manager
On September 15th, a supply chain attack targeting the Node Package Manager (npm) ecosystem was discovered. A package maintainer’s account was compromised and malicious code was injected into widely used JavaScript packages. One of the payloads injected was a worm-type malware known as Shai-Hulud. It was also deduced by Palo Alto Networks unit 42 that for some of the bash scripts used in the attack, an LLM was used as a co-author.