GitHub Worm Hits npm Packages With 16M Downloads
Key Takeaways Mini Shai-Hulud exploited GitHub Actions on May 19, compromising 300+ npm packages across 16M weekly downloads. The malware installs a dead-man’s switch that wipes the developer’s machine if the stolen npm token is revoked. GitHub responded May 20 with staged publishing, bulk OIDC onboarding, and a plan to deprecate legacy npm tokens. Mini…
