Sophisticated Supply Chain Attack Exploits npm's Trusted Publishing, Compromises Hundreds of Packages
A critical supply chain attack has rocked the open-source ecosystem, leveraging a subtle GitHub Actions misconfiguration to compromise hundreds of npm packages. The 'mini shy hulude' worm bypassed traditional security measures, leading to widespread infection and unprecedented persistence mechanisms.