←back to thread

1208 points jamesberthoty | 2 comments | | HN request time: 0.443s | source
Show context
GuB-42 ◴[] No.45261656[source]
> Shai Hulud

Clever name... but I would have expected malware authors to be a bit less obvious. They literally named their giant worm after a giant worm.

> At the core of this attack is a ~3.6MB minified bundle.js file

Yep, even malware can be bloated. That's in the spirit of NPM I guess...

replies(2): >>45261672 #>>45262396 #
1. jsheard ◴[] No.45261672[source]
I suppose it's only a matter of time before one of these supply chain attacks unintentionally pulls in a second, unrelated supply chain attack.
replies(1): >>45268849 #
2. beeflet ◴[] No.45268849[source]
fish grow to the meet the size of the fishbowl