Wednesday, September 17, 2025

New best story on Hacker News: Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised

Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised
1129 by jamesberthoty | 917 comments on Hacker News.
A lot of blogs on this are AI generated and such as this is developing, so just linking to a bunch of resources out there: Socket: - Sep 15 (First post on breach): https://socket.dev/blog/tinycolor-supply-chain-attack-affect... - Sep 16: https://socket.dev/blog/ongoing-supply-chain-attack-targets-... StepSecurity – https://ift.tt/ZaLkwyi... Aikido - https://ift.tt/I3D8ZUy... Ox - https://ift.tt/SZDV16x... Safety - https://ift.tt/g1EzTKp Phoenix - https://ift.tt/ok1KUyu Semgrep - https://ift.tt/UNheHfm...

New best story on Hacker News: Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised

Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised 1129 by jamesberthoty | 917 comments on Hacker News. A lot of b...