All posts

June 3, 2026

Anatomy of the Shai-Hulud npm Worm (And How To Catch The Next One)

In September 2025 a self-replicating worm compromised 180+ npm packages overnight — including CrowdStrike's.

npmwormsupply-chainincident-response

Catch the next supply-chain attack on the PR that adds it.

14-day free trial · no card required