The Register Home Page

back to article Shai-Hulud malware worms Red Hat npm package versions downloaded 80K times a week

Security researchers on Monday found dozens of Red Hat npm package releases infected with the Mini Shai-Hulud worm that TeamPCP cybercriminals recently open-sourced. The new supply chain attack hit at least 32 npm package releases published under the Red Hat Cloud Services namespace, according to security researchers from …

  1. Anonymous Coward
    Anonymous Coward

    very confusing article

    next time i should re-read the title...

    I would still like to know how the RedHat employee got hacked. Hopefully it was using his work computer to visit a non-work-related site.

  2. Albert Coates Bronze badge
    Mushroom

    Really?

    Hey, El Reg, a couple of months ago this sort of article used to garner many tens of comments within hours - and now, barely zilch. What could possibly have gone wrong? Is it perhaps that no-one gives a fuck any more? Obviously nothing to do with your fuckwitted re-vamp and shitting on your loyal fans. Bye bye, El Reg: do you even give yourselves six months? Generous in the extreme, I know.

    1. drankinatty Silver badge

      Re: Really?

      Not sure what motivated your response, I did re-read it a couple times, the point I see here isn't a revamped npm report, but yet another factual report of a supply chain poisoning with npm being the vector of choice for the bad guys. Maybe I'm just too old to get it, but I've always welcomed accurate reporting that keeps you apprised of the pervasive security exploits, even if it does sound a lot like the one three days go. The frequency and the vector are the point.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon