Technology ❯ Cybersecurity ❯ Malware
npm Packages Credential Theft Python Packages Open Source Software npm Worms NPM Packages npm Ecosystem GitHub Actions GlassWorm Sha1-Hulud
Stolen GitHub credentials let poisoned releases run a Bun‑launched infostealer that harvests developer and cloud secrets, repackages them, and propagates through npm.