Security · 1h ago
Four New Supply Chain Attacks Target npm and PyPI Credentials
Between June and July 14, four supply chain attacks hit npm and PyPI, including a PyPI variant of the Shai-Hulud worm, typosquatted payment SDKs, a stolen publishing token, and a hijacked CI pipeline. The attacks targeted developer credentials and build pipelines, with over 100 packages and 471 malicious artifacts linked to the Miasma and Hades worms. Attackers used varied entry points but shared the goal of stealing credentials from developer environments.
Meridian48 take
The diversity of attack vectors underscores that credential hygiene remains the weak link in open-source ecosystems, making this a systemic issue beyond any single fix.
Read the full reporting
The Streak Continues: Four More Supply Chain Attacks Hit npm and PyPI →
DEV Community
supply-chain-attacksnpm-pypi