‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supply-chain attack
Source: CyberScoop · Category: Supply Chain
Mini Shai-Hulud malware compromised hundreds of open-source packages across major registries using forged release signatures. Law firms must immediately audit all open-source dependencies in firm systems and client code for presence of malicious versions; review software bill-of-materials (SBOM) processes.