Get the latest tech news

SHA1-Hulud the Second Comming – Postman, Zapier, PostHog All Compromised via NPM


The threat actor behind “Shai Hulud 2.0” launched a new malware campaign compromising the supply chain of Zapier, ENS Domains and more — exposing secrets, injecting malicious code, and enabling widespread developer-environment takeover.

None

Get the Android app

Or read this on Hacker News

Read more on:

Photo of npm

npm

Photo of PostHog

PostHog

Photo of Postman

Postman

Related news:

News photo

NPM flooded with malicious packages downloaded more than 86,000 times

News photo

Postman which I thought worked locally on my computer, is down

News photo

Cleaning house in Nx monorepo, how i removed unused deps safely