Supply Chain
Shai-Hulud: the first self-propagating npm worm (2025), explained
Most supply-chain incidents are a single bad package. Shai-Hulud was different: it used what it stole to publish itself into more packages, on its own.
Tag
Most supply-chain incidents are a single bad package. Shai-Hulud was different: it used what it stole to publish itself into more packages, on its own.
Most dependency supply-chain risk is blunted by three boring npm settings. They are not glamorous, but they remove the easy ways a bad package slips in.
Your app ships dozens of packages you never chose. When one gets hijacked, you ship the attack too. Here is the pattern, the big recent incidents, and the defenses.