The malware employs ecosystem-specific techniques for execution. On npm, many packages use post-install hooks to deploy a comprehensive JavaScript payload ...
The Shai-Hulud supply-chain malware campaign is exploiting the automated systems developers trust to publish software safely.