Sponsor of the Day:
Jerkmate
https://securelist.com/shai-hulud-2-0/118214/
Nothing to steal? Let’s wipe. We’re analyzing the Shai Hulud 2.0 npm worm | Securelist
Dec 4, 2025 - Kaspersky researchers uncover new version of Shai Hulud nom worm, which attacks targets in Russia, India, Brazil, China and other countries, and has wiper...
shai hulud 20 npmnothingstealwipe
https://safedep.io/shai-hulud-second-coming-supply-chain-attack/
Shai-Hulud 2.0 npm Supply Chain Attack Technical Analysis - Real-time Open Source Software Supply...
Critical npm supply chain attack compromises zapier-sdk, @asyncapi, posthog, and @postman packages with self-replicating malware. Technical analysis reveals...
shai hulud 2npm supply chainanalysis real timeopen source software
https://securitylabs.datadoghq.com/articles/shai-hulud-2.0-npm-worm/
The Shai-Hulud 2.0 npm worm: analysis, and what you need to know | Datadog Security Labs
Learn more about the Shai-Hulud 2.0 npm worm.
shai hulud 2datadog security labs0 npmwormanalysis
https://www.aikido.dev/blog/shai-hulud-2-0-unknown-wonderer-supply-chain-attack
Shai Hulud 2.0: What the Unknown Wonderer Reveals About the Attackers’ Endgame
Dec 3, 2025 - New research into the Shai Hulud 2.0 malware suggests the username UnknownWonderer1 tells us more about the attackers’ endgame.
shai hulud 20unknownrevealsendgame