Shai-Hulud 2.0 Supply Chain Compromise

were compromised Multiple npm packages from various web servicesthrough account takeover/developer compromise. A malicious actor was able to add a stealthy loader to the package.json file that locates the Bun runtime, silently installs, then executes a malicious script. Our investigation has shown…

dev

Sources