GeistHaus
log in · sign up

Mini Shai-Hulud Strikes Again: 314 npm Packages Compromised

safedep.io

A compromised npm maintainer account published 631 malicious versions across 314 packages including size-sensor, echarts-for-react, timeago.js, and hundreds of @antv scoped packages, affecting 15M+ monthly downloads.

5 pages link to this URL