Live updates: Shai-hulud, the most dangerous NPM breach in history

by chhaon 9/16/2025, 6:26 PMwith 3 comments

by btownon 9/16/2025, 6:46 PM

Larger discussion thread here: https://news.ycombinator.com/item?id=45260741

by bikeshavingon 9/16/2025, 7:09 PM

If you’re a package maintainer, please defensively revoke all NPM and GitHub tokens. This is a worm which is still spreading and you probably don’t want to publish anything today anyways, so you might as well use this incident as an opportunity to rotate everything.