Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Big attack on NPM – Shai-Hulud 2.0 (about.gitlab.com)
2 points by thomasfl 54 days ago | hide | past | favorite | 3 comments


Made a package (that I needed personally), to easily reinstall all dependencies (using the same versions) in a project and check them using Aikido's safe chain for malware (supported npm, pnpm, bun, and yarn). It also easily switches a project's package manager to another. https://www.npmjs.com/package/eazypm



This is a nasty npm attack. It steals API keys and credits.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: