Summary:
Wes Bos and Scott Tolinski break down "Mini Shai Hulud," a supply chain attack that hit popular JavaScript packages including TanStack. They explain how attackers abused GitHub Actions cache poisoning via pull_request_target to steal npm publishing credentials—without ever compromising a maintainer's password—then trace how the worm propagated across packages, including a destructive dead man's switch, and cover practical protections for both maintainers and consumers. Linked to the readable episode transcript.
Excerpt:
"This was not somebody getting any of their credentials stolen at all."
#Supply Chain Security#npm#GitHub Actions#Security
Read Full Source