home.social

#koisecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #koisecurity, aggregated by home.social.

  1. Self-Replicating Worm Affected Several Hundred #NPM Packages, Including CrowdStrike's -Slashdot

    The Shai-Hulud #malware campaign impacted across multiple maintainers, reports #KoiSecurity , including popular libraries like @ctrl/tinycolor & some packages maintained by #CrowdStrike.

    Malicious versions embed a #trojanized script (bundle.js) designed to steal developer #credentials, exfiltrate secrets, and persist in repositories and endpoints through automated workflows

    it.slashdot.org/story/25/09/20