Hackers can bypass npm’s Shai-Hulud defenses via Git dependencies
ID: 9a8054db-a9b3-5a1e-9750-aab8b0c992ce
STIX ID: report--9a8054db-a9b3-5a1e-9750-aab8b0c992ce
Feed Name: Bleeping Computer
Threat Score
Researchers discovered multiple vulnerabilities (PackageGate) in JavaScript package managers that let Git-based dependencies override configuration (e.g., .npmrc) and execute arbitrary code even when lifecycle scripts are disabled; fixes were released for Bun, pnpm and vlt, but npm dismissed the report, raising significant supply-chain and code-execution risk tied to past Shai-Hulud malware activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
