news.mlab.sh
Back to the feed
supply-chain

The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15)

High
Image: Palo Alto Unit 42
Summary

The npm ecosystem experienced a critical inflection point in September 2025 with the emergence of the Shai-Hulud worm, marking a shift from nuisance attacks to a high-consequence threat landscape. Since then, Unit 42 has observed an aggressive acceleration in supply chain compromises, evolving from isolated typosquatting to systematic campaigns by various threat actors. The latest campaigns, including ‘Mini Shai-Hulud’ and ‘miasma-train-p1’, demonstrate increasingly sophisticated techniques, including decentralized C2 infrastructure, self-propagation, and leveraging CI/CD pipelines to evade human review. The Red Hat supply chain attack in June 2026, involving over 80,000 downloads, highlighted the significant impact of these attacks and the need for robust remediation strategies.

Read the full article at Palo Alto Unit 42

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.