Posts tagged with #npm

Cybercriminals Open-Source npm Malware for $5,000 Competition, Critical Flaw Limits Impact

A cybercriminal group known as Team PCP open-sourced their 'Shai-Hulud' malware on GitHub, launching a $5,000 competition to incentivize further attacks on the npm ecosystem. Despite the audacious move, a critical flaw in the malware itself significantly limited its potential impact, though it still prompted projects like Nuxt to re-evaluate security protocols.