INCIDENT EVIDENCE GRAPH
The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15)
Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The post The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) appeared first on Unit 42 .
- Victim: npm ecosystem, npm package users
- Actor: Multiple threat actors targeting npm ecosystem
- Exploit: Post-Shai Hulud supply chain vulnerabilities
- Method: Wormable malware, CI/CD persistence, multi-stage attacks, obfuscation, credential harvesting