logo

Hackers can bypass npm’s Shai-Hulud defenses via Git dependencies

ID: 9a8054db-a9b3-5a1e-9750-aab8b0c992ce

STIX ID: report--9a8054db-a9b3-5a1e-9750-aab8b0c992ce

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-01-26

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Researchers discovered multiple vulnerabilities (PackageGate) in JavaScript package managers that let Git-based dependencies override configuration (e.g., .npmrc) and execute arbitrary code even when lifecycle scripts are disabled; fixes were released for Bun, pnpm and vlt, but npm dismissed the report, raising significant supply-chain and code-execution risk tied to past Shai-Hulud malware activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.