What Happened
- A report described a new supply-chain attack wave (“Mini Shai-Hulud”) in which 314 npm packages were compromised, showing how npm lifecycle scripts can propagate malware through transient dependencies and confirming execution-risk remains high during normal installs.
- A report described a new supply-chain attack wave (“Mini Shai-Hulud”) in which 314 npm packages were compromised, showing how npm lifecycle scripts can propagate malware through transient dependencies and confirming execution-risk remains high during normal installs.
- 1 evidence item attached for review.