Shai-Hulud 2.0 Supply Chain Compromise
were compromised Multiple npm packages from various web servicesthrough account takeover/developer compromise. A malicious actor was able to add a stealthy loader to the package.json file that locates the Bun runtime, silently installs, then executes a malicious script. Our investigation has shown…
Sources
- T1Shai-Hulud 2.0 Supply Chain CompromiseVercel (blog + changelog)