GeistHaus
log in · sign up

How we got hit by Shai-Hulud: A complete post-mortem | Trigger.dev

trigger.dev

On November 25th, one of our engineers was compromised by the Shai-Hulud npm supply chain worm. Here's what happened, how we responded, and what we've changed.

2 pages link to this URL
Last Week in Security (LWiS) - 2025-12-15

Moonwalk++ stack telemetry bypass (@KlezVirus), a pile of Mediatek CVEs (@hyprdude), AppleScript decompiler (@__pberba__), SCOM hacking (@unsigned_sh0rt + @breakfix), .NET SOAP disaster (@chudyPB), and more!

0 inbound links article en